CVE-2026-18591

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 08:17

Updated : 2026-08-12 21:00


NVD link : CVE-2026-18591

Mitre link : CVE-2026-18591

CVE.ORG link : CVE-2026-18591


JSON object : View

Products Affected

No product.

CWE
CWE-310

Cryptographic Issues

CWE-312

Cleartext Storage of Sensitive Information