PatchSiren cyber security CVE debrief
CVE-2026-5457 PropertyGuru CVE debrief
A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unknown function of the file com/allproperty/android/agentnet/BuildConfig.java of the component com.allproperty.android.agentnet. The manipulation of the argument SEGMENT_ANDROID_WRITE_KEY/SEGMENT_TOS_WRITE_KEY results in use of hard-coded cryptographic key. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks.
- Vendor
- PropertyGuru
- Product
- AgentNet Singapore App
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of PropertyGuru AgentNet Singapore App up to 23.7.10 on Android should be aware of this security flaw and take necessary precautions to protect their data. This includes reviewing installed applications, monitoring for suspicious activity, and applying vendor remediation if available.
Technical summary
The vulnerability is caused by a hard-coded cryptographic key in the file com/allproperty/android/agentnet/BuildConfig.java of the component com.allproperty.android.agentnet. An attacker with local access can exploit this vulnerability by manipulating the argument SEGMENT_ANDROID_WRITE_KEY/SEGMENT_TOS_WRITE_KEY, leading to the use of a hard-coded cryptographic key. This security flaw affects PropertyGuru AgentNet Singapore App up to 23.7.10 on Android, and defenders should review installed applications, monitor for suspicious activity, and apply vendor remediation if available to protect their data. The exploit has been released to the public and may be used for attacks, emphasizing the need for precautions.
Defensive priority
Low priority, as the attack requires local access and the CVSS score is 1.9. However, defenders should still take precautions to protect their data and systems.
Recommended defensive actions
- Inventory and verify affected PropertyGuru AgentNet Singapore App installations up to 23.7.10 on Android.
- Apply vendor remediation if available.
- Monitor for suspicious local activity.
- Use compensating controls such as encryption and secure key management.
- Review and update asset inventory to ensure accurate tracking of affected systems.
- Implement additional monitoring and detection measures to identify potential exploitation attempts.
- Track exceptions and retest remediated assets to ensure the vulnerability is properly addressed.
Evidence notes
The CVE record was published on 2026-04-03T07:16:20.793Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerability. Defenders should verify affected systems and review vendor guidance for remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5457 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5457
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5457 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5457
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/781764
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/355045
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/355045/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.