CVE-2026-18591 Details
Description
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
A vulnerability exists in the Meesho Online Shopping App, specifically in the component com.meesho.supply, for Android versions prior to 20260607. This vulnerability allows for the manipulation of user-related arguments, such as user ID, phone number, email address, and name, leading to the insecure storage of sensitive information in cleartext. The exposed data includes Personally Identifiable Information (PII) and session details, which can be accessed directly from the physical device. The vulnerability has been publicly disclosed, and the vendor was notified before this disclosure.
Users are advised to update to the latest version of the Meesho Online Shopping App, as the vulnerability has been reported to the vendor.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1tUOME-DfuTVDnbCxvDPKNAZjrRl0GmJQ/view | [email protected] | Partial ContentVideo |
| https://github.com/honestcorrupt/MEESHO-CVE_REQUEST_NEW | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-18591 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/850975 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/385419 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/385419/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-310 | Cryptographic Issues | [email protected] |
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Meesho | <= 20260607 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion