Security Vulnerability in MobSF Mobile Application Testing Tool
CVE-2026-68927

3LOW

Key Information:

Vendor

Mobsf

Vendor
CVE Published:
18 August 2026

What is CVE-2026-68927?

A significant vulnerability exists in the MobSF mobile application security testing tool that allows authenticated users to upload malicious APK files. These crafted APKs can exploit a weakness in the way the application validates the Android manifest, specifically its handling of the android:host attribute combined with a separately supplied android:port in the URL. This flaw can potentially enable attackers to direct requests to a nonstandard port on an attacker-controlled hostname, facilitating illicit access to internal services. The issue has been addressed in MobSF version 4.5.1, which mitigates the risk associated with these types of requests.

Affected Version(s)

Mobile-Security-Framework-MobSF < 4.5.1

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.