Unauthorized Access in Datadog Android Application Vulnerability
CVE-2026-47363

6.3MEDIUM

Key Information:

Vendor

Datadog

Vendor
CVE Published:
7 August 2026

What is CVE-2026-47363?

The Datadog Android application contains a significant vulnerability in its launcher activity, AppActivity, which is marked as android:exported="true". This exposure allows any app installed on the device to invoke the launcher with arbitrary session extras, leading to unauthorized access to user identities, access tokens, and permissions. The vulnerability arises from the system's acceptance of injected session data during the onCreate and onNewIntent methods without appropriate permission checks or server-side token validation. As a result, an attacker can exploit this flaw using their own OAuth access tokens, potentially gaining automatic login access to the victim's Datadog account and sensitive information, posing a substantial security threat.

Affected Version(s)

Android App 5.9.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mark Esler
.