PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5456 Align Technology CVE debrief

A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key. The attack must be carried out locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Users of Align Technology My Invisalign App 3.12.4 on Android should be aware of this vulnerability and take necessary precautions.

Vendor
Align Technology
Product
My Invisalign App
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Align Technology My Invisalign App 3.12.4 on Android should be aware of this vulnerability and take necessary precautions. This includes reviewing and verifying affected versions of My Invisalign App on Android, applying vendor patch if available, and implementing compensating controls to monitor and restrict access to sensitive data.

Technical summary

The vulnerability involves a hard-coded cryptographic key in the My Invisalign App 3.12.4 on Android, specifically in the file com/aligntech/myinvisalign/BuildConfig.java. This could potentially allow local attackers to exploit the vulnerability. The impacted element is an unknown function of the file. The vendor was contacted early about this disclosure but did not respond in any way. Users of Align Technology My Invisalign App 3.12.4 on Android should review compensating controls for exposed systems while remediation is scheduled and verified, and consider alternative solutions until a vendor patch is available.

Defensive priority

Low priority due to local attack vector and low CVSS score. However, defenders should still review compensating controls for exposed systems while remediation is scheduled and verified.

Recommended defensive actions

  • Inventory and verify affected versions of My Invisalign App on Android
  • Apply vendor patch if available
  • Implement compensating controls to monitor and restrict access to sensitive data
  • Consider alternative solutions until vendor patch is available
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-04-03T07:16:20.570Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android, specifically in the file com/aligntech/myinvisalign/BuildConfig.java. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key. The attack must be carried out locally. The exploit is publicly available and might be used.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5456 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5456

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5456 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5456

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.