Junglewise Threat Intelligence

CVE-2026-26228: VideoLAN VLC for Android path traversal in Remote Access Server

CVE-2026-26228 · Severity: medium · CVSS 4.9 · Published 2026-02-26

Executive brief

VLC for Android, a popular media player app, contains a security flaw in its Remote Access Server feature. An authorized user on the same network could exploit this to access files on the device that they should not be able to see. While the impact is limited by Android's built-in security protections, it could still expose private application data or internal files.

Technical details

A path traversal vulnerability exists in the Remote Access Server component of VLC for Android. The 'file' query parameter in the authenticated 'GET /download' endpoint is concatenated into a filesystem path without proper canonicalization or directory containment checks. An authenticated attacker with network reachability can exploit this to request files outside the designated download directory. The exploit's impact is restricted by the Android application sandbox, generally limiting file access to app-internal and app-specific external storage. The issue is resolved in version 3.7.0.

Affected products

  • VideoLAN VLC for Android Prior to 3.7.0

Timeline

  • 2026-02-23: patched: Version 3.7.0 released
  • 2026-02-26: advisory: Initial NVD publication

References

Related threats