PatchSiren cyber security CVE debrief
CVE-2026-40000 ZTE CVE debrief
The CVE record for CVE-2026-40000 was published on 2026-07-27T10:16:37.907Z and has not been modified since then. This CVE describes a vulnerability in the FilePreViewActivity of ZTE File Manager, which allows third-party applications to access arbitrary files with elevated privileges. This could potentially expose sensitive data in system directories such as /data/data and /data/local/tmp on unrooted devices. Users of ZTE File Manager, especially those with unrooted devices, should be aware of this vulnerability and take necessary precautions.
- Vendor
- ZTE
- Product
- A75 Pro 5G
- CVSS
- LOW 1.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-28
Who should care
Users of ZTE File Manager, especially those with unrooted devices, should be aware of this vulnerability and take necessary precautions. This includes reviewing and updating ZTE File Manager to the latest version, restricting access to FilePreViewActivity, and monitoring for suspicious activity. Additionally, operators and security teams should review the official advisory and CVE record to understand the affected scope and severity.
Technical summary
The FilePreViewActivity in ZTE File Manager allows third-party applications to access arbitrary files with elevated privileges, potentially exposing sensitive data in system directories. This vulnerability could allow unrooted devices to read files under certain system directories such as /data/data and /data/local/tmp. The vulnerability is due to the improper handling of file paths in the FilePreViewActivity, which can be exploited by third-party applications to access sensitive data.
Defensive priority
Low priority due to low CVSS score and limited attack surface.
Recommended defensive actions
- Review and update ZTE File Manager to the latest version
- Restrict access to FilePreViewActivity
- Monitor for suspicious activity
- Implement additional security controls for untrusted applications
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The evidence for this CVE is limited, and further verification is needed to confirm vulnerability details. The CVE record was published on 2026-07-27T10:16:37.907Z and has not been modified since then. The FilePreViewActivity in ZTE File Manager allows third-party applications to access arbitrary files with elevated privileges, potentially exposing sensitive data in system directories. However, the exact scope of affected products and versions is not clearly documented. Defenders should verify the official advisory and CVE record for more information and review compensating controls for exposed systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40000 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40000
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40000 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40000
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/7341653040963675660
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.