CVE-2026-47363
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/08/2026
Last modified:
08/08/2026
Description
In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend.<br />
This requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim&#39;s app.<br />
Impact: A co-installed application can switch the victim&#39;s Datadog app to a session the attacker controls. This is an account-confusion issue; it does not by itself expose the victim&#39;s existing session or data.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM


