MEDIUMCVSS 4.4Vulnerability

CVE-2026-84852

A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument _display_name leads to path traversal. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
MEDIUM
cvss_score
4.4
cvss_severity
MEDIUM
retrieved_at
2026-09-29T00:56:32+00:00
score
4.4
last_source
NVD
cve_id
CVE-2026-84852
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
signal_observed_at
2026-09-29T00:56:32+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
published_at
2026-09-02T20:17:42.050
last_modified
2026-09-28T23:10:00.143

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84852 (CVSS 4.4) — Ninja Signal Threat Intelligence | Ninja Signal