PatchSiren cyber security CVE debrief
CVE-2026-5458 Noelse CVE debrief
A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone.noelse. This manipulation of the argument SEGMENT_WRITE_KEY causes use of hard-coded cryptographic key. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Users of Noelse Individuals & Pro App up to 2.1.7 on Android should be aware of this weakness and take necessary precautions to protect their application and data.
- Vendor
- Noelse
- Product
- Individuals & Pro App
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Noelse Individuals & Pro App up to 2.1.7 on Android should be aware of this weakness and take necessary precautions to protect their application and data. This includes reviewing the configuration and implementation of the application, ensuring that the latest security patches are applied, and monitoring for potential attacks.
Technical summary
The weakness is located in the file com/reactnative/antelop/BuildConfig.java of the component com.afone.noelse in Noelse Individuals & Pro App up to 2.1.7 on Android. The manipulation of the argument SEGMENT_WRITE_KEY causes the use of a hard-coded cryptographic key. The attack requires local access. Users of Noelse Individuals & Pro App up to 2.1.7 on Android should be aware of this weakness and take necessary precautions to protect their application and data.
Defensive priority
Low priority, as the attack needs to be launched locally and the CVSS score is 1.9.
Recommended defensive actions
- Inventory and verify the version of Noelse Individuals & Pro App installed on Android devices.
- Apply patches or updates provided by the vendor, if available.
- Implement compensating controls, such as monitoring and exception tracking, to detect and respond to potential attacks.
- Consider using additional security measures, such as encryption and secure key management.
- Review and update incident response plans to address potential attacks.
- Conduct regular security audits and risk assessments to identify and mitigate potential vulnerabilities.
- Monitor for and respond to potential attacks on affected systems.
Evidence notes
The CVE record was published on 2026-04-03T07:16:21.037Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone.noelse. The manipulation of the argument SEGMENT_WRITE_KEY causes use of hard-coded cryptographic key. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T07:16:21.037Z and has not been modified since then. The NVD entry is currently Deferred.