LOWVulnerability
CVE-2026-81301
Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then supports query(), openFile(), and delete() operations. Because the provider is exported and lacks android:permission, android:readPermission, or android:writePermission, another local application can access the provider authority and cause File Manager's process to read, create, overwrite, or delete files that are accessible to that process.
Properties
- cve_id
- CVE-2026-81301
- signal_observed_at
- 2026-09-23T22:45:07+00:00
- published_at
- 2026-09-14T16:17:19.360
- last_modified
- 2026-09-18T19:44:10.957
Related Entities (2)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]
Explore deeper with Ninja Signal's threat intelligence graph