Exported Activity Vulnerability in Datadog Android Application
CVE-2026-44964

6.5MEDIUM

Key Information:

Vendor

Datadog

Vendor
CVE Published:
7 August 2026

What is CVE-2026-44964?

The Datadog Android application contains a significant vulnerability due to the OnCallNotificationActivity being declared with 'android:exported="true"' in the AndroidManifest.xml without any permission restrictions. This flaw allows any other application co-installed on the same device to launch it, exploiting attacker-controlled Intent extras. When an attacker sends these Intents, they can trigger a forged Acknowledge request to the Datadog backend using the authenticated session of a victim user. Furthermore, this access to the activity allows the attacker to invoke functions that could dismiss the device's keyguard and turn on the screen, paving the way for social engineering attacks or basic annoyance tactics. The exploitation requires a malicious application on the same device as the victim and an active session within the Datadog app.

Affected Version(s)

Android App 5.9.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mark Esler
.