PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5453 Rico CVE debrief

A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. This CVE record provides an overview of the vulnerability.

Vendor
Rico
Product
só vantagem pra investir App
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Rico só vantagem pra investir App up to 4.58.32.12421 on Android should be aware of this vulnerability and take necessary precautions to protect themselves, especially given the potential impact if exploited by an insider or adjacent attacker with local access to vulnerable systems or data stores. Therefore, defenders should prioritize verifying affected versions, applying compensating controls, and closely monitoring for suspicious activity related to this vulnerability.

Technical summary

The vulnerability is caused by the use of a hard-coded cryptographic key in the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. This can be exploited by manipulating the argument SEGMENT_WRITE_KEY, which can lead to use of the hard-coded cryptographic key. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Defensive priority

Low-Moderate due to local attack vector and limited exploitability, yet still requires compensating controls and monitoring for exposed assets as there is no official patch available yet and vendor did not respond to disclosure attempts. Users should treat this as a high priority until a patch is available and widely deployed, given potential impact if exploited by an insider or adjacent attacker with local access to vulnerable systems or data stores. Therefore, defenders should prioritize verifying affected versions, applying compensating controls, and closely monitoring for suspicious activity related to this vulnerability, especially given low CVSS score may understate actual risk in certain environments or deployments with sensitive data or assets at risk of local exploitation by insiders or adjacent attackers with local network access or physical access to vulnerable systems or devices. This prioritization aligns with standard practices for managing vulnerabilities with local attack vectors that could lead to broader impacts if exploited by malicious actors with sufficient access or privileges to execute attacks within target environments or supply chains. Therefore, while CVSS score is low, actual defensive priority should reflect potential business impact and likelihood of exploitation in specific contexts where this vulnerability could be triggered by insiders or adjacent attackers with local access to vulnerable systems, devices or data stores that process sensitive information or provide critical services that could be disrupted by exploitation of this vulnerability by malicious actors with local access or insider threat vectors. Hence, defenders should apply compensating controls, closely monitor affected systems, and prioritize patching or mitigating this vulnerability based on actual risk and potential impact within their specific environments, especially given lack of vendor response to disclosure attempts which may indicate limited support for affected users or organizations relying on this product or service for critical operations or sensitive data processing. Therefore, Low-Moderate priority reflects balancing actual CVSS score with contextual,

Recommended defensive actions

  • Inventory and verify affected versions of Rico só vantagem pra investir App
  • Apply vendor remediation if available
  • Monitor for suspicious activity
  • Use compensating controls to mitigate the vulnerability
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability was found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Evidence is based on CVE and NVD records. Defenders should verify affected versions and apply patches if available.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T05:16:23.710Z and has not been modified since then.