PatchSiren cyber security CVE debrief
CVE-2026-92862 Wavedash Co., Ltd. CVE debrief
The Android application 'Ticket Ryutsu Center' from Wavedash Co., Ltd. improperly handles custom URL schemes. This vulnerability allows a malicious application to cause access to an arbitrary website via a crafted Intent. The CVSS score is 3.3, indicating a low severity. Defenders should verify the version of the application, restrict custom URL schemes, and monitor for suspicious activity. The vulnerability has a CVSS score of 3.3 and is considered low severity. The CVE record and source item provide information about the vulnerability in 'Ticket Ryutsu Center'. The vendor, Wavedash Co., Ltd., is the affected vendor. The vulnerability is related to custom URL schemes and allows
- Vendor
- Wavedash Co., Ltd.
- Product
- Ticket Ryutsu Center
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for managing and securing Android applications, particularly those using 'Ticket Ryutsu Center', should be aware of this vulnerability and take necessary actions to verify and mitigate the risk.
Why it matters
The CVE-2026-92862 vulnerability in 'Ticket Ryutsu Center' allows a malicious application to access an arbitrary website via a crafted Intent. Defenders should verify the version of the application, restrict custom URL schemes, and monitor for suspicious activity. The vulnerability has a CVSS score of 3.3 and is considered low severity.
- Defenders need to verify if their systems or applications use the vulnerable 'Ticket Ryutsu Center' application and assess the risk of exploitation.
- This vulnerability could allow a malicious application to access arbitrary websites, potentially leading to phishing or other malicious activities.
- Defenders should prioritize patching or updating the 'Ticket Ryutsu Center' application to prevent exploitation.
- The vulnerability's impact is limited to the application's ability to access arbitrary websites, and it does not allow for arbitrary code execution or data theft.
Technical summary
The 'Ticket Ryutsu Center' application for Android does not properly handle custom URL schemes. This can be exploited by a malicious application to access an arbitrary website via a crafted Intent. The vulnerability has a CVSS score of 3.3 and is considered low severity.
Defensive priority
Defenders should prioritize verifying the version of 'Ticket Ryutsu Center' and ensuring that it is not vulnerable to this issue.
Recommended defensive actions
- Verify the version of 'Ticket Ryutsu Center' and ensure it is not vulnerable
- Restrict the use of custom URL schemes in the application
- Monitor for suspicious activity related to the application
Evidence notes
The CVE record and source item provide information about the vulnerability in 'Ticket Ryutsu Center'. The vendor, Wavedash Co., Ltd., is the affected vendor. The vulnerability is related to custom URL schemes and allows access to an arbitrary website.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92862 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92862
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92862 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92862
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CVE-2026-92862
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/92xxx/CVE-2026-92862.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://jvn.jp/en/jp/JVN53292492/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.