CVE-2026-2974 Details
Description
A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The manipulation of the argument accessToken/refreshToken/metadata/key_derivation_params/auth_methods leads to exposure of backup file to an unauthorized control sphere. An attack has to be approached locally. The attack is considered to have high complexity. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. Upgrading to version 0.26.0 is able to resolve this issue. The identifier of the patch is 873ecc03f92238e162f98a068ad56069a922b4f6/0bd662320174d8265dfe3b05a04bc13efc960532. It is recommended to upgrade the affected component. The creator of the software explains: "Because of AliasVault's zero-knowledge encryption design, the tokens stored in aliasvault.xml are API session tokens that cannot decrypt the vault on their own: the master password is required for that. So while this isn't a direct vault compromise risk, there's no reason to include them in backups either."
A vulnerability exists in the AliasVault App for both Android and iOS, specifically in versions up to 0.25.3. The issue arises from the app's backup handler, which improperly includes sensitive data stored in plaintext within the shared_prefs/aliasvault.xml file. This file contains access tokens, refresh tokens, metadata, key derivation parameters, and authentication methods. While the app's zero-knowledge encryption design means these tokens cannot independently decrypt vault contents, their inclusion in backups poses a risk of credential compromise. The vulnerability requires local exploitation and has a high complexity level.
Users are advised to upgrade to AliasVault version 0.26.0, which disables backups for the app's data on both Android and iOS. Instructions for updating are available in the AliasVault update guides.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aliasvault/aliasvault/commit/873ecc03f92238e162f98a068ad56069a922b4f6 | [email protected] | Patch |
| https://github.com/aliasvault/aliasvault/issues/1497 | [email protected] | Issue Tracking |
| https://github.com/aliasvault/aliasvault/issues/1497#issue-3855176470 | [email protected] | Issue Tracking |
| https://github.com/aliasvault/aliasvault/pull/1499 | [email protected] | Issue Tracking |
| https://github.com/aliasvault/aliasvault/releases/tag/0.26.0 | [email protected] | Release Notes |
| https://vuldb.com/?ctiid.347340 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.347340 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.756058 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.756059 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
| CWE-530 | Exposure of Backup File to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aliasvault aliasvault | <= 0.25.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 12, 2026 | Initial Analysis | [email protected] |
| Feb 23, 2026 | New CVE Received | [email protected] |