Credential Storage Vulnerability in La Nacion App on Android
CVE-2026-4243
Key Information:
- Vendor
La Nacion
- Status
- Vendor
- CVE Published:
- 16 March 2026
Badges
What is CVE-2026-4243?
A vulnerability has been discovered in the La Nacion App version 10.2.25 for Android, where improper handling of the API_KEY_WEBSOCKET_CV parameter may lead to unprotected storage of sensitive credentials. This flaw exists within a specific component of the application and is particularly concerning as it permits local exploitation. The complexity level for successfully executing this attack is regarded as high, making it challenging to exploit. Nevertheless, details regarding the exploit have been released publicly, raising concerns over potential exploitation methods. Despite early notification to the vendor about this issue, no response has been received.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
La Nacion App 10.2.25
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
