Access Control Vulnerability in YAMAP - Social Trekking GPS App by Yamap
CVE-2026-85125

5.1MEDIUM

Key Information:

Vendor

Yamap Inc.

Vendor
CVE Published:
14 September 2026

What is CVE-2026-85125?

The YAMAP - Social Trekking GPS App has an improper access control vulnerability within its WebView implementation. This security flaw may allow unauthorized information leakage, potentially exposing sensitive data or redirecting users to unintended and possibly harmful websites. Users should be vigilant and consider updating the app or reviewing security practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

YAMAP -Social Trekking GPS App 0 <= 17.1.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.