CVE-2026-0025
published 2026-03-02CVE-2026-0025: In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation…
PriorityP345high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.10%
1.0th percentile
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | frameworks_base | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2:0 < 16-qpr2:2026-03-01 | 16-qpr2:2026-03-01 |
| platform | frameworks_base | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r35x-v8qq-pcqp: In hasImage of Notification
ghsa_unreviewed·2026-03-02
CVE-2026-0025 [HIGH] CWE-200 GHSA-r35x-v8qq-pcqp: In hasImage of Notification
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0025: In hasImage of Notification
osv·2026-03-01
CVE-2026-0025 CVE-2026-0025: In hasImage of Notification
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0025 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2026-0025 [HIGH] CVE-2026-0025 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0025 :
NixOS vulnerability analysis and mitigation
In hasImage of Notification.java, there is a possible way to reveal information across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source : NVD
## 8.4
Score
Published March 2, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
android
Sources
NVD
Nix Severity HIGH No Fix Added at: Mar 04, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs
Bugzilla
CVE-2026-58344 moodle: CSRF risk in quiz attempt regrading [fedora-all]
bugzilla·2026-07-28
CVE-2026-58344 [MEDIUM] CVE-2026-58344 moodle: CSRF risk in quiz attempt regrading [fedora-all]
CVE-2026-58344 moodle: CSRF risk in quiz attempt regrading [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
MSA-26-0025: CSRF risk in quiz attempt regrading
Description: The regrade action in the quiz overview report did not
include the necessary token to prevent a CSRF risk.
Issue summary: CSRF risk in quiz attempt regrading
Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88531
Bugzilla
CVE-2026-58344 moodle: CSRF risk in quiz attempt regrading
bugzilla·2026-06-30
CVE-2026-58344 [MEDIUM] CVE-2026-58344 moodle: CSRF risk in quiz attempt regrading
CVE-2026-58344 moodle: CSRF risk in quiz attempt regrading
MSA-26-0025: CSRF risk in quiz attempt regrading
Description: The regrade action in the quiz overview report did not
include the necessary token to prevent a CSRF risk.
Issue summary: CSRF risk in quiz attempt regrading
Severity/Risk: Serious
Versions affected: 5.2, 5.1 to 5.1.4, 5.0 to 5.0.7, 4.5 to 4.5.11 and earlier
unsupported versions
Versions fixed: 5.2.1, 5.1.5, 5.0.8 and 4.5.12
Reported by: Paul Holden
Issue no.: MDL-88531
2026-03-02
Published