CVE-2026-5452 Details
Description
A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This manipulation causes use of hard-coded cryptographic key . The attack can only be executed locally. The exploit has been published and may be used.
A vulnerability exists in the UCC CampusConnect App for Android, affecting versions up to 14.3.5. The issue arises from a hard-coded Uploadcare private key in the BuildConfig.java file of the campusconnect.ucc component. This vulnerability allows an unauthenticated user to access the Uploadcare API and perform file operations such as uploading, downloading, listing, and deleting files from the Uploadcare bucket. Such actions could lead to unauthorized disclosure of sensitive information, permanent data loss, or, if a malicious file is uploaded and processed by the affected website's server, remote code execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 3, 2026CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/781757 | [email protected] | Technical Description |
| https://vuldb.com/vuln/355040 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/vuln/355040/cti | [email protected] | AdvisoryPermission Required |
| https://www.notion.so/Uploadcare-Private-Key-Exposure-Leading-to-Unauthorized-File-Operations-and-Potential-RCE-in-campusc-3262de3f97fb8057bc67ec4320672d99?source=copy_link | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-320 | Key Management Errors | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| UCC CampusConnect App | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | New CVE Received | [email protected] |
Volerion