CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oppo:coloros_assistant:1.4.26:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-30 09:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22070

Mitre link : CVE-2026-22070

CVE.ORG link : CVE-2026-22070


JSON object : View

Products Affected

oppo

  • coloros_assistant
CWE
CWE-23

Relative Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')