SQLite Database Vulnerability in Datadog Android App by Datadog
CVE-2026-47362

4.6MEDIUM

Key Information:

Vendor

Datadog

Vendor
CVE Published:
7 August 2026

What is CVE-2026-47362?

The Datadog Android application exposes sensitive data through unencrypted SQLite databases. Operationally critical content, such as notification details and recent searches, is stored in plaintext, making it vulnerable to unauthorized access, especially on rooted or jailbroken devices. Security risks include physical device acquisition and misconfigured application settings that allow for easy extraction of data. The lack of encryption mechanisms like SQLCipher exacerbates this threat, highlighting the need for robust data protection strategies for applications handling sensitive information.

Affected Version(s)

Android App 5.9.4

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mark Esler
.