CVE-2026-0024
published 2026-03-02CVE-2026-0024: In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check…
PriorityP417medium4CVSS 3.1
AVLACLPRNUINSUCLINAN
EPSS
0.09%
0.7th percentile
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_providers_mediaprovider | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | packages_providers_mediaprovider | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | packages_providers_mediaprovider | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | packages_providers_mediaprovider | >= 16-qpr2:0 < 16-qpr2:2026-03-01 | 16-qpr2:2026-03-01 |
| platform | packages_providers_mediaprovider | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgxv-wpwx-67mq: In isRedactionNeededForOpenViaContentResolver of MediaProvider
ghsa_unreviewed·2026-03-02
CVE-2026-0024 [MEDIUM] CWE-862 GHSA-fgxv-wpwx-67mq: In isRedactionNeededForOpenViaContentResolver of MediaProvider
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0024: In isRedactionNeededForOpenViaContentResolver of MediaProvider
osv·2026-03-01
CVE-2026-0024 CVE-2026-0024: In isRedactionNeededForOpenViaContentResolver of MediaProvider
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0024 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2026-0024 [MEDIUM] CVE-2026-0024 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0024 :
NixOS vulnerability analysis and mitigation
In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of media due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Source : NVD
## 4
Score
Published March 2, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
android
Sources
NVD
Nix Severity MEDIUM No Fix Added at: Mar 04, 2026
## Get a CVE risk asse
Bugzilla
CVE-2026-58343 moodle: Missing capability checks in AI placement web services [fedora-all]
bugzilla·2026-07-28
CVE-2026-58343 [MEDIUM] CVE-2026-58343 moodle: Missing capability checks in AI placement web services [fedora-all]
CVE-2026-58343 moodle: Missing capability checks in AI placement web services [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MSA-26-0024: Missing capability checks in AI placement web services
Description: Capability checks were missing from course assistance AI
placement web services, which could allow users to make
requests to those AI course assistance web services without
having the relevant capabilities (if those features are
enabled).
Issue summary: Missing capability checks in AI placement web services
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and e
Bugzilla
CVE-2026-58343 moodle: Missing capability checks in AI placement web services
bugzilla·2026-06-30
CVE-2026-58343 [MEDIUM] CVE-2026-58343 moodle: Missing capability checks in AI placement web services
CVE-2026-58343 moodle: Missing capability checks in AI placement web services
MSA-26-0024: Missing capability checks in AI placement web services
Description: Capability checks were missing from course assistance AI
placement web services, which could allow users to make
requests to those AI course assistance web services without
having the relevant capabilities (if those features are
enabled).
Issue summary: Missing capability checks in AI placement web services
Severity/Risk: Minor
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88533
2026-03-02
Published