CVE-2026-5458 | Noelse Individuals & Pro App up to 2.1.7 on Android com.afone.noelse BuildConfig.java SEGMENT_WRITE_KEY hard-coded key
A vulnerability was found in Noelse Individuals & Pro App up to 2.1.7 on Android. It has been classified as problematic. This impacts an unknown function of the file com/reactnative/antelop/BuildConfig.java of the component com.afone.noelse. This manipulation of the argument SEGMENT_WRITE_KEY causes use of hard-coded cryptographic key
.
This vulnerability is registered as CVE-2026-5458. The attack needs to be launched locally. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.