Junglewise Threat Intelligence

CVE-2026-5452: UCC CampusConnect App hard-coded cryptographic key in BuildConfig

CVE-2026-5452 · Severity: low · CVSS 3.3 · Published 2026-04-03

Executive brief

The UCC CampusConnect mobile application for Android contains a security flaw where a secret cryptographic key is permanently embedded in the app's code. A person with local access to the device could potentially extract this key to access protected information or perform unauthorized actions within the app's ecosystem. This could lead to the exposure of private data or unauthorized file operations.

Technical details

A hard-coded cryptographic key vulnerability (CWE-321) exists in the UCC CampusConnect Android application up to version 14.3.5. The flaw is located within the 'campusconnect/BuildConfig.java' file of the 'campusconnect.ucc' component. An attacker with local access to the device or the application's binary can extract this static key. According to external research, this exposure may involve Uploadcare private keys, which could lead to unauthorized file operations or potential remote code execution depending on how the key is utilized by the backend services. A proof-of-concept exploit has been published.

Affected products

  • UCC CampusConnect App up to 14.3.5

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References