MEDIUM
dongdongbh
CVE published 2026-10-09
CVE-2026-107857
The Mindwtr mobile app, prior to version 1.1.5, stores Cloud sync bearer tokens and WebDAV passwords in plaintext within unencrypted AsyncStorage. This vulnerability, CVE-2026-107857, poses a medium-severity risk as it allows parties with access to the application database or exposed device backups to recover these credentials. Consequently, they could access synchronized tasks and attachments. To mitigat [truncated]