Task Management Application Vulnerability in Mindwtr by Dongdongbh
CVE-2026-107857

4.4MEDIUM

Key Information:

Vendor

Dongdongbh

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107857?

The Mindwtr application, a free offline-first task management tool, has a significant security flaw in its prior versions before 1.1.5. The mobile application inadvertently writes sensitive information, including the Cloud sync bearer token and WebDAV password, to unencrypted AsyncStorage. This exposure allows unauthorized users to retrieve these credentials if they have access to the application database or a compromised device backup. Consequently, this vulnerability can lead to unauthorized access to synchronized tasks and attachments, compromising user privacy and data integrity. The issue has been addressed in version 1.1.5.

Affected Version(s)

Mindwtr < 1.1.5

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.