Back to overview

CVE-2026-12190

MEDIUM
5.3
CVSS 3.1
Description
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of the component ai.mainfunc.genspark. The manipulation leads to improper authorization in handler for custom url scheme. The attack can only be performed from a local environment. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-12190
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-14 06:38 UTC
Published
2026-06-14 22:45 UTC
Last updated
2026-06-15 10:37 UTC
Primary CWE
CWE-939
Improper Authorization in Handler for Custom URL Scheme
Vendor / Product
Genspark / AI Workspace App
Sources
cve.org  ·  NVD

Severity & Metrics

5.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Genspark AI Workspace App 2.8.4
Weakness (CWE)
CWESourceDescription
CWE-285 cna Improper Authorization
CWE-939 cna Improper Authorization in Handler for Custom URL Scheme
CVSS scores (4)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R
5.3 MEDIUM 3.0 cna CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R
4.8 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
4.3 N/D 2.0 cna AV:L/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:UR
References (5)
Back to overview