PatchSiren cyber security CVE debrief
CVE-2026-47363 Datadog CVE debrief
The Datadog Android application, prior to version v541-5.9.2, contains an exported launcher activity AppActivity that accepts an attacker-supplied session, including OAuth tokens, from Intent extras without proper permission guard. This allows a co-installed malicious application to switch the victim's Datadog app to a session controlled by the attacker, resulting in an account-confusion issue. The vulnerability requires a malicious application co-installed on a device with the Datadog app and an OAuth token the attacker is willing to load into the victim's app. The impact is limited to account confusion and does not expose the victim's existing session or data. To address this issue, organizations should prioritize updating to the latest version of the Datadog Android application. This involves verifying that the application is properly configured and validated to prevent potential account-confusion issues. Additionally, monitoring for potential issues and maintaining an inventory of affected assets are recommended. Rolling back changes or implementing compensating controls may be necessary while remediation is scheduled and verified. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are crucial steps in the remediation process. Source tracking and maintaining awareness of the issue's status are vital for ensuring the security of the affected systems.
- Vendor
- Datadog
- Product
- Android App
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-09-03
Who should care
Organizations using the Datadog Android application prior to v541-5.9.2 should be aware of the potential account-confusion issue and take steps to update to the latest version. This issue affects operators of the Datadog Android application, particularly those responsible for vulnerability management and security teams. They should review the official CVE Program record and NIST NVD detail page for source-provided CVE metadata and vulnerability assessment to understand the affected scope and severity. Additionally, they should verify that the Datadog Android application is properly configured and validated to prevent potential account-confusion issues. Monitoring for potential issues and maintaining an inventory of affected assets are also recommended. Rolling back changes or implementing compensating controls may be necessary while remediation is scheduled and verified. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are crucial steps in the remediation process. Source tracking and maintaining awareness of the issue's status are vital for ensuring the security of the affected systems. To ensure the security of their systems, organizations should also consider implementing additional security measures such as monitoring and detection, and reviewing relevant logs for exposed assets that need extra review. This will help to prevent potential account-confusion issues and ensure the security of the affected systems. Furthermore, organizations should review their asset inventory and consider implementing compensating controls for exposed systems while remediation is scheduled and verified. This can include reviewing relevant monitoring, detection, and logs for exposed assets that need extra review. By taking these steps, organizations can help to prevent potential account-confusion issues and ensure the security of their systems. In addition to updating to the latest version of the Datadog Android application, organizations should also consider implementing a robust vulnerability management program to identify and address potential vulnerabilities in their systems. This can include regular security assessments,
Technical summary
The Datadog Android application prior to v541-5.9.2 has an account-confusion issue due to the exported launcher activity AppActivity accepting an attacker-supplied session without validation, allowing a co-installed application to switch the victim's Datadog app to a session controlled by the attacker. This issue requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim's app. The impact is an account-confusion issue; it does not by itself expose the victim's existing session or data. To address this, organizations should prioritize updating to the latest version of the Datadog Android application.
Defensive priority
Organizations using the Datadog Android application prior to v541-5.9.2 should prioritize updating to the latest version to prevent potential account-confusion issues.
Recommended defensive actions
- Update the Datadog Android application to version v541-5.9.2 or later
- Verify that the Datadog Android application is properly configured and validated
- Monitor for potential account-confusion issues
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record indicates that the Datadog Android application prior to v541-5.9.2 has an account-confusion issue due to the exported launcher activity AppActivity accepting an attacker-supplied session without validation. To verify, defenders should review the official CVE Program record and NIST NVD detail page for source-provided CVE metadata and vulnerability assessment. The affected product scope and severity are detailed in these records, but additional review is necessary to confirm exposure and plan mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47363 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47363
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47363 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47363
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cwe.mitre.org/data/definitions/926.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.