Description
Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions.

The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then supports query(), openFile(), and delete() operations. Because the provider is exported and lacks android:permission, android:readPermission, or android:writePermission, another local application can access the provider authority and cause File Manager's process to read, create, overwrite, or delete files that are accessible to that process.
Published: 2026-09-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Access
Action: Immediate Patch
AI Analysis

Impact

Ekia File Manager 1.2.7 exposes an Android ContentProvider that is exported without any caller permission checks. The provider maps the URI path supplied by the Java File constructor directly to a filesystem path. Because no readPermission, writePermission, or android:permission attribute is declared, any application on the same device can invoke the provider’s query, openFile, or delete methods and read, create, overwrite, or delete files that the File Manager process can access. This flaw allows an attacker to compromise confidentiality, integrity, and availability of local files, potentially leaking sensitive data or corrupting user files.

Affected Systems

The vulnerable product is Ekia File Manager, version 1.2.7, running on Android devices. All installations of this version are impacted, regardless of the device model or Android release, as the flaw is built into the ContentProvider.

Risk and Exploitability

The risk is high due to the local nature of the attack vector and the lack of permission checks on the exported provider. With a CVSS score of 8.5, an attacker can read, create, overwrite, or delete any file the File Manager’s process can access, compromising confidentiality, integrity, and availability of local data. The EPSS score of < 1% indicates a low but non‑zero probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The local attack surface, however, means that an adversary with a malicious Android application on the device could exploit the flaw without external network access.

Generated by OpenCVE AI on September 20, 2026 at 23:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest patched version of Ekia File Manager from a trusted source.
  • If an update is not available, uninstall the impacted application to remove the attack surface.
  • Contact Ekia support to confirm that a fix has been released and to obtain guidance on available work‑arounds.

Generated by OpenCVE AI on September 20, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then supports query(), openFile(), and delete() operations. Because the provider is exported and lacks android:permission, android:readPermission, or android:writePermission, another local application can access the provider authority and cause File Manager's process to read, create, overwrite, or delete files that are accessible to that process.
Title Ekia File Manager 1.2.7 - Exported ContentProvider allows unauthorized file access
First Time appeared Ekia
Ekia file Manager
Weaknesses CWE-926
CPEs cpe:2.3:a:ekia:file_manager:1.2.7:*:android:*:*:*:*:*
Vendors & Products Ekia
Ekia file Manager
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Ekia File Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-09-14T19:23:00.039Z

Reserved: 2026-08-26T17:38:45.889Z

Link: CVE-2026-81301

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:13.775Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:19.360

Modified: 2026-09-18T19:44:10.957

Link: CVE-2026-81301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T06:30:18Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components