CVE-2026-5804 Details
Description
An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings.
A vulnerability allowing improper authentication has been identified in the Motorola Factory Test component (com.motorola.motocit) on Motorola phones with a Security Patch Level prior to 2026-04-05. This vulnerability arises from a reference to a writable file descriptor in external storage, which third-party apps can exploit to open a TCP server. This exposure of sensitive permissions and data could enable a local attacker to bypass permission checks and access protected device settings.
Users are advised to update their Motorola phones to the latest software version. The vulnerability is fixed in versions with a Security Patch Level of 2026-04-05 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://en-us.support.motorola.com/app/answers/detail/a_id/192534 | [email protected] |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | [email protected] |