PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92862 Wavedash Co., Ltd. CVE debrief

The Android application 'Ticket Ryutsu Center' from Wavedash Co., Ltd. improperly handles custom URL schemes. This vulnerability allows a malicious application to cause access to an arbitrary website via a crafted Intent. The CVSS score is 3.3, indicating a low severity. Defenders should verify the version of the application, restrict custom URL schemes, and monitor for suspicious activity. The vulnerability has a CVSS score of 3.3 and is considered low severity. The CVE record and source item provide information about the vulnerability in 'Ticket Ryutsu Center'. The vendor, Wavedash Co., Ltd., is the affected vendor. The vulnerability is related to custom URL schemes and allows

Vendor
Wavedash Co., Ltd.
Product
Ticket Ryutsu Center
CVSS
LOW 3.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for managing and securing Android applications, particularly those using 'Ticket Ryutsu Center', should be aware of this vulnerability and take necessary actions to verify and mitigate the risk.

Why it matters

The CVE-2026-92862 vulnerability in 'Ticket Ryutsu Center' allows a malicious application to access an arbitrary website via a crafted Intent. Defenders should verify the version of the application, restrict custom URL schemes, and monitor for suspicious activity. The vulnerability has a CVSS score of 3.3 and is considered low severity.

  • Defenders need to verify if their systems or applications use the vulnerable 'Ticket Ryutsu Center' application and assess the risk of exploitation.
  • This vulnerability could allow a malicious application to access arbitrary websites, potentially leading to phishing or other malicious activities.
  • Defenders should prioritize patching or updating the 'Ticket Ryutsu Center' application to prevent exploitation.
  • The vulnerability's impact is limited to the application's ability to access arbitrary websites, and it does not allow for arbitrary code execution or data theft.

Technical summary

The 'Ticket Ryutsu Center' application for Android does not properly handle custom URL schemes. This can be exploited by a malicious application to access an arbitrary website via a crafted Intent. The vulnerability has a CVSS score of 3.3 and is considered low severity.

Defensive priority

Defenders should prioritize verifying the version of 'Ticket Ryutsu Center' and ensuring that it is not vulnerable to this issue.

Recommended defensive actions

  • Verify the version of 'Ticket Ryutsu Center' and ensure it is not vulnerable
  • Restrict the use of custom URL schemes in the application
  • Monitor for suspicious activity related to the application

Evidence notes

The CVE record and source item provide information about the vulnerability in 'Ticket Ryutsu Center'. The vendor, Wavedash Co., Ltd., is the affected vendor. The vulnerability is related to custom URL schemes and allows access to an arbitrary website.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92862 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92862

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92862 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92862

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CVE-2026-92862

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/92xxx/CVE-2026-92862.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://jvn.jp/en/jp/JVN53292492/

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.