Description
Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from the affected application.
Published: 2026-09-15
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure via Intent
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an improper access control in a component of the ManabiPocket for Parents Android app. An attacker can craft an Intent targeting that component, which the app accepts without validating the caller, allowing a malicious third‑party app to retrieve sensitive data that should be protected. This weakness corresponds to CWE‑926. The impact is that personal or parental data stored or displayed by the app could be accessed by an attacker.

Affected Systems

The affected product is the ManabiPocket for Parents application from NTT DOCOMO BUSINESS, Inc. for Android devices. All releases that contain the vulnerable component are potentially affected until a vendor patch is released. No specific version details are available, and the CNA did not publish an affected‑version list.

Risk and Exploitability

The CVSS score of 1.8 indicates a low overall severity. The EPSS score of <1% shows a very low likelihood that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the victim to have an Android device with the vulnerable app installed and to install a malicious app that can target the component via an Intent. If such conditions exist, the attacker could read sensitive data through the exposed component.

Generated by OpenCVE AI on September 17, 2026 at 18:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any patch or update released by NTT DOCOMO BUSINESS for ManabiPocket for Parents that fixes the Intent access control issue.
  • If a patch is not yet available, uninstall or disable the application until an update is issued to eliminate the vulnerable component.
  • Use Android's permission and intent filtering settings (or a security app) to block unauthorized apps from sending Intents to exported components, and keep the device OS and security suite up to date.

Generated by OpenCVE AI on September 17, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Android Intent Component Enables Data Theft

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ntt Docomo Business
Ntt Docomo Business manabipocket For Parents
Vendors & Products Ntt Docomo Business
Ntt Docomo Business manabipocket For Parents

Wed, 16 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Android Intent Component Enables Data Theft

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Description Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, potentially allowing the malicious application to obtain sensitive information from the affected application.
Weaknesses CWE-926
References
Metrics cvssV3_0

{'score': 2.5, 'vector': 'CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Ntt Docomo Business Manabipocket For Parents
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-15T17:44:13.623Z

Reserved: 2026-09-11T06:51:42.376Z

Link: CVE-2026-86701

cve-icon Vulnrichment

Updated: 2026-09-15T17:43:54.896Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:16:59.200

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-86701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-926

    Improper Export of Android Application Components