PatchSiren cyber security CVE debrief
CVE-2026-5456 Align Technology CVE debrief
A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unknown function of the file com/aligntech/myinvisalign/BuildConfig.java of the component com.aligntech.myinvisalign.emea. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key. The attack must be carried out locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Users of Align Technology My Invisalign App 3.12.4 on Android should be aware of this vulnerability and take necessary precautions.
- Vendor
- Align Technology
- Product
- My Invisalign App
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Align Technology My Invisalign App 3.12.4 on Android should be aware of this vulnerability and take necessary precautions. This includes reviewing and verifying affected versions of My Invisalign App on Android, applying vendor patch if available, and implementing compensating controls to monitor and restrict access to sensitive data.
Technical summary
The vulnerability involves a hard-coded cryptographic key in the My Invisalign App 3.12.4 on Android, specifically in the file com/aligntech/myinvisalign/BuildConfig.java. This could potentially allow local attackers to exploit the vulnerability. The impacted element is an unknown function of the file. The vendor was contacted early about this disclosure but did not respond in any way. Users of Align Technology My Invisalign App 3.12.4 on Android should review compensating controls for exposed systems while remediation is scheduled and verified, and consider alternative solutions until a vendor patch is available.
Defensive priority
Low priority due to local attack vector and low CVSS score. However, defenders should still review compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Inventory and verify affected versions of My Invisalign App on Android
- Apply vendor patch if available
- Implement compensating controls to monitor and restrict access to sensitive data
- Consider alternative solutions until vendor patch is available
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-03T07:16:20.570Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android, specifically in the file com/aligntech/myinvisalign/BuildConfig.java. The manipulation of the argument CDAACCESS_TOKEN leads to use of hard-coded cryptographic key. The attack must be carried out locally. The exploit is publicly available and might be used.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T07:16:20.570Z and has not been modified since then. The NVD entry is currently Deferred.