Junglewise Threat Intelligence

CVE-2026-18058: Motorola Smart Connect dashboard UI manipulation via privilege escalation

CVE-2026-18058 · Severity: high · CVSS 7.5 · Published 2026-09-02

Executive brief

The Motorola Smart Connect mobile app's dashboard UI can be manipulated by malicious third-party applications. When combined with a phishing attack that tricks users into interacting with malicious links, an attacker can gain unauthorized elevated privileges within the Smart Connect system, potentially compromising connected devices and enabling unauthorized control or data access.

Technical details

The vulnerability is a UI injection and missing authorization flaw (CWE-862) in the Motorola Smart Connect Android application. The root cause is insufficient authorization checks that allow third-party apps to manipulate the Smart Connect dashboard UI. The attack requires local code execution (adjacent/local network), a phishing link that the user must interact with, and user action (UI interaction), but can result in privilege escalation and device compromise. The vulnerability affects Smart Connect app versions prior to 9.03.00.61 and is fixed in that version along with the latest monthly security patches. CVSS 3.1 score is 7.5 (High); CVSS 4.0 score is 7.3 (High).

Affected products

  • Motorola Smart Connect prior to 9.03.00.61

Timeline

  • 2026-09-02: disclosed

References