PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5456 Align Technology CVE debrief

A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key. The attack must be carried out locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Users of Align Technology My Invisalign App 3.12.4 on Android should be aware of this vulnerability and take necessary precautions.

Vendor
Align Technology
Product
My Invisalign App
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Align Technology My Invisalign App 3.12.4 on Android should be aware of this vulnerability and take necessary precautions. This includes reviewing and verifying affected versions of My Invisalign App on Android, applying vendor patch if available, and implementing compensating controls to monitor and restrict access to sensitive data.

Technical summary

The vulnerability involves a hard-coded cryptographic key in the My Invisalign App 3.12.4 on Android, specifically in the file com/aligntech/myinvisalign/BuildConfig.java. This could potentially allow local attackers to exploit the vulnerability. The impacted element is an unknown function of the file. The vendor was contacted early about this disclosure but did not respond in any way. Users of Align Technology My Invisalign App 3.12.4 on Android should review compensating controls for exposed systems while remediation is scheduled and verified, and consider alternative solutions until a vendor patch is available.

Defensive priority

Low priority due to local attack vector and low CVSS score. However, defenders should still review compensating controls for exposed systems while remediation is scheduled and verified.

Recommended defensive actions

  • Inventory and verify affected versions of My Invisalign App on Android
  • Apply vendor patch if available
  • Implement compensating controls to monitor and restrict access to sensitive data
  • Consider alternative solutions until vendor patch is available
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-04-03T07:16:20.570Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android, specifically in the file com/aligntech/myinvisalign/BuildConfig.java. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key. The attack must be carried out locally. The exploit is publicly available and might be used.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T07:16:20.570Z and has not been modified since then. The NVD entry is currently Deferred.