CVE-2026-0020
published 2026-03-02CVE-2026-0020: In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass…
PriorityP345high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.10%
0.9th percentile
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | frameworks_base | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2:0 < 16-qpr2:2026-03-01 | 16-qpr2:2026-03-01 |
| platform | frameworks_base | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvfx-pp4f-92h6: In parsePermissionGroup of ParsedPermissionUtils
ghsa_unreviewed·2026-03-02
CVE-2026-0020 [HIGH] CWE-639 GHSA-cvfx-pp4f-92h6: In parsePermissionGroup of ParsedPermissionUtils
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0020: In parsePermissionGroup of ParsedPermissionUtils
osv·2026-03-01
CVE-2026-0020 CVE-2026-0020: In parsePermissionGroup of ParsedPermissionUtils
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0020 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2026-0020 [HIGH] CVE-2026-0020 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0020 :
NixOS vulnerability analysis and mitigation
In parsePermissionGroup of ParsedPermissionUtils.java, there is a possible way to bypass a consent dialog to obtain permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source : NVD
## 8.4
Score
Published March 2, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
android
Sources
NVD
Nix Severity HIGH No Fix Added at: Mar 04, 2026
## Get a CVE risk assessme
Bugzilla
CVE-2026-58339 moodle: Reflected XSS via Feedback import error message [fedora-all]
bugzilla·2026-07-28
CVE-2026-58339 [MEDIUM] CVE-2026-58339 moodle: Reflected XSS via Feedback import error message [fedora-all]
CVE-2026-58339 moodle: Reflected XSS via Feedback import error message [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MSA-26-0020: Reflected XSS via Feedback import error message
Description: The Feedback activity module's import functionality
required additional sanitizing to prevent a reflected XSS
risk.
Issue summary: Reflected XSS via Feedback import error message
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88543
Bugzilla
CVE-2026-58339 moodle: Reflected XSS via Feedback import error message
bugzilla·2026-06-30
CVE-2026-58339 [MEDIUM] CVE-2026-58339 moodle: Reflected XSS via Feedback import error message
CVE-2026-58339 moodle: Reflected XSS via Feedback import error message
MSA-26-0020: Reflected XSS via Feedback import error message
Description: The Feedback activity module's import functionality
required additional sanitizing to prevent a reflected XSS
risk.
Issue summary: Reflected XSS via Feedback import error message
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88543
2026-03-02
Published