PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47363 Datadog CVE debrief

The Datadog Android application, prior to version v541-5.9.2, contains an exported launcher activity AppActivity that accepts an attacker-supplied session, including OAuth tokens, from Intent extras without proper permission guard. This allows a co-installed malicious application to switch the victim's Datadog app to a session controlled by the attacker, resulting in an account-confusion issue. The vulnerability requires a malicious application co-installed on a device with the Datadog app and an OAuth token the attacker is willing to load into the victim's app. The impact is limited to account confusion and does not expose the victim's existing session or data. To address this issue, organizations should prioritize updating to the latest version of the Datadog Android application. This involves verifying that the application is properly configured and validated to prevent potential account-confusion issues. Additionally, monitoring for potential issues and maintaining an inventory of affected assets are recommended. Rolling back changes or implementing compensating controls may be necessary while remediation is scheduled and verified. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are crucial steps in the remediation process. Source tracking and maintaining awareness of the issue's status are vital for ensuring the security of the affected systems.

Vendor
Datadog
Product
Android App
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-03
Advisory published
2026-08-07
Advisory updated
2026-09-03

Who should care

Organizations using the Datadog Android application prior to v541-5.9.2 should be aware of the potential account-confusion issue and take steps to update to the latest version. This issue affects operators of the Datadog Android application, particularly those responsible for vulnerability management and security teams. They should review the official CVE Program record and NIST NVD detail page for source-provided CVE metadata and vulnerability assessment to understand the affected scope and severity. Additionally, they should verify that the Datadog Android application is properly configured and validated to prevent potential account-confusion issues. Monitoring for potential issues and maintaining an inventory of affected assets are also recommended. Rolling back changes or implementing compensating controls may be necessary while remediation is scheduled and verified. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are crucial steps in the remediation process. Source tracking and maintaining awareness of the issue's status are vital for ensuring the security of the affected systems. To ensure the security of their systems, organizations should also consider implementing additional security measures such as monitoring and detection, and reviewing relevant logs for exposed assets that need extra review. This will help to prevent potential account-confusion issues and ensure the security of the affected systems. Furthermore, organizations should review their asset inventory and consider implementing compensating controls for exposed systems while remediation is scheduled and verified. This can include reviewing relevant monitoring, detection, and logs for exposed assets that need extra review. By taking these steps, organizations can help to prevent potential account-confusion issues and ensure the security of their systems. In addition to updating to the latest version of the Datadog Android application, organizations should also consider implementing a robust vulnerability management program to identify and address potential vulnerabilities in their systems. This can include regular security assessments,

Technical summary

The Datadog Android application prior to v541-5.9.2 has an account-confusion issue due to the exported launcher activity AppActivity accepting an attacker-supplied session without validation, allowing a co-installed application to switch the victim's Datadog app to a session controlled by the attacker. This issue requires a malicious application co-installed on a device with the Datadog app installed, and an OAuth token the attacker is willing to load into the victim's app. The impact is an account-confusion issue; it does not by itself expose the victim's existing session or data. To address this, organizations should prioritize updating to the latest version of the Datadog Android application.

Defensive priority

Organizations using the Datadog Android application prior to v541-5.9.2 should prioritize updating to the latest version to prevent potential account-confusion issues.

Recommended defensive actions

  • Update the Datadog Android application to version v541-5.9.2 or later
  • Verify that the Datadog Android application is properly configured and validated
  • Monitor for potential account-confusion issues
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record indicates that the Datadog Android application prior to v541-5.9.2 has an account-confusion issue due to the exported launcher activity AppActivity accepting an attacker-supplied session without validation. To verify, defenders should review the official CVE Program record and NIST NVD detail page for source-provided CVE metadata and vulnerability assessment. The affected product scope and severity are detailed in these records, but additional review is necessary to confirm exposure and plan mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47363 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47363

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47363 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47363

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.