Description
A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key
. The attack must be carried out locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-04-03
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local cryptographic key misuse
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the BuildConfig.java file of the My Invisalign App where a hard‑coded cryptographic key is used when processing the CDAACCESS_TOKEN argument. An adversary who can run code locally on an infected device could read or tamper with data that is encrypted with this key, resulting in potential disclosure or manipulation of sensitive information. The weakness corresponds to hard‑coded secrets and use of a hard‑coded encryption key.

Affected Systems

The affected product is Align Technology’s My Invisalign App version 3.12.4 for Android, specifically the com.aligntech.myinvisalign.emea component. No other versions or platforms are listed as affected.

Risk and Exploitability

A CVSS score of 4.8 places the vulnerability in the moderate range, and the publicly available exploit suggests that an attacker who can run code on the device can take advantage of the hard‑coded key. Because the attack must be carried out locally, the threat is limited to devices that have already been compromised or are used by personnel who can execute code within the app. The lack of EPSS data and absence from the CISA KEV catalog indicate that the vulnerability has not yet been widely exploited, but the local nature does not eliminate the risk of data compromise if an insider or malicious user gains device access.

Generated by OpenCVE AI on April 3, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify installed My Invisalign App version; upgrade to the latest release if available.
  • If no patch exists, remove or obfuscate the hard‑coded key and avoid using CDAACCESS_TOKEN for encryption.
  • Contact Align Technology to request an official security fix and ensure communication is tracked.
  • Monitor device logs for abnormal use of CDAACCESS_TOKEN or attempts to retrieve the hard‑coded key.

Generated by OpenCVE AI on April 3, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Align Technology
Align Technology my Invisalign App
Vendors & Products Align Technology
Align Technology my Invisalign App

Fri, 03 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key . The attack must be carried out locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Align Technology My Invisalign App com.aligntech.myinvisalign.emea BuildConfig.java hard-coded key
Weaknesses CWE-320
CWE-321
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Align Technology My Invisalign App
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-03T15:37:33.677Z

Reserved: 2026-04-02T22:19:54.687Z

Link: CVE-2026-5456

cve-icon Vulnrichment

Updated: 2026-04-03T15:37:30.532Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-03T07:16:20.570

Modified: 2026-04-03T16:10:23.730

Link: CVE-2026-5456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-03T09:15:42Z

Weaknesses