File Access Vulnerability in ZTE File Manager
CVE-2026-40000
Key Information:
- Vendor
Zte
- Status
- Vendor
- CVE Published:
- 27 July 2026
Badges
What is CVE-2026-40000?
The ZTE File Manager contains a vulnerability in its FilePreViewActivity which allows third-party applications to invoke this activity and provide arbitrary file paths. This behavior could potentially enable unauthorized access to various sensitive files within system directories such as /data/data and /data/local/tmp, assuming that proper access restrictions are not enforced. If exploited, this could lead to significant data exposure on unrooted devices, thus compromising user privacy and security.
Affected Version(s)
Blade A75 5G A75 series project, versions released before 2026/05/30
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
