PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47364 Datadog CVE debrief

The Datadog Android application, prior to version v545-5.9.2, tags Crashlytics data with the user's Datadog UUID without providing a user-facing opt-out. This results in the user's UUID and crash data being visible within Firebase Crashlytics. Organizations should review and update their installations to prevent potential user data exposure. The CVE record was published on 2026-08-07T18:17:17.217Z and has not been modified since then. The CVSS score for this vulnerability is 6.5, indicating a medium severity level.

Vendor
Datadog
Product
Android App
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-09-03
Advisory published
2026-08-07
Advisory updated
2026-09-03

Who should care

Organizations using the Datadog Android application, particularly those with sensitive user data, should review and update their installations to prevent potential user data exposure in Firebase Crashlytics. This includes reviewing Firebase Crashlytics configuration to restrict access to sensitive user data and monitoring user data exposure. Security teams and vulnerability management teams should prioritize this vulnerability due to its potential impact on user data privacy and security posture related to crash data visibility in Firebase Crashlytics. Operators of affected systems should verify and apply the vendor-supplied patch to ensure opt-out functionality for Crashlytics data tagging and implement compensating controls as needed to mitigate potential exposure risks associated with this vulnerability in the interim until patching can be completed across all affected systems and assets that rely on the Datadog Android application for monitoring and analytics purposes within their environments. This vulnerability may impact organizations that rely on Firebase Crashlytics for crash reporting and analysis, especially those in regulated industries handling sensitive user information. Therefore, a thorough review of the current security controls and configurations is recommended to ensure adequate protection against potential exploitation of this vulnerability within their environments. Additionally, asset inventory management and configuration reviews should be conducted to identify and remediate any instances of the vulnerable application, ensuring alignment with organizational security policies and compliance requirements related to data privacy and protection. Monitoring and detection capabilities should also be reviewed and enhanced to identify potential exploitation attempts or anomalous activity related to this vulnerability in the environment. Overall, a comprehensive review and update of security controls, configurations, and monitoring capabilities are necessary to address the potential risks associated with this vulnerability in the Datadog Android application. The vulnerability management team should track exceptions, retest remediated assets, and a

Technical summary

The Datadog Android application prior to v545-5.9.2 tags Crashlytics data with the user's Datadog UUID without providing a user-facing opt-out. This results in the user's UUID and crash data being visible within Firebase Crashlytics. The CVSS score for this vulnerability is 6.5, indicating a medium severity level. The vulnerability is classified as CWE-200, Information Exposure. Datadog Android app versions prior to v545-5.9.2 are affected.

Defensive priority

Medium-priority defensive review recommended due to potential user data exposure in Firebase Crashlytics, with a CVSS score of 6.5.

Recommended defensive actions

  • Review and update the Datadog Android application to version v545-5.9.2 or later to ensure opt-out functionality for Crashlytics data tagging.
  • Verify Firebase Crashlytics configuration to restrict access to sensitive user data.
  • Monitor user data exposure in Firebase Crashlytics and implement compensating controls as needed.
  • Conduct a thorough review of the current security controls and configurations to ensure adequate protection against potential exploitation of this vulnerability within your environment.
  • Review and enhance monitoring and detection capabilities to identify potential exploitation attempts or anomalous activity related to this vulnerability in the environment.
  • Perform asset inventory management and configuration reviews to identify and remediate any instances of the vulnerable application.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

Evidence from the NVD and CVE Program records indicates that Datadog Android app versions prior to v545-5.9.2 tagged Crashlytics data with user UUIDs without opt-out. User UUID and crash data visible in Firebase Crashlytics.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47364 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47364

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47364 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47364

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.