Junglewise Threat Intelligence

CVE-2026-5456: Align Technology My Invisalign App hard-coded key in BuildConfig

CVE-2026-5456 · Severity: low · CVSS 3.3 · Published 2026-04-03

Executive brief

A security vulnerability was found in the My Invisalign mobile application for Android, which is used by patients to track their dental alignment progress. The app contains a hard-coded security token that could allow an attacker with local access to the device to gain unauthorized access to certain backend environments. This could potentially lead to the exposure of internal configuration data or content management systems.

Technical details

The My Invisalign App (v3.12.4) for Android contains a hard-coded cryptographic key/token (CDAACCESS_TOKEN) within the BuildConfig.java file of the com.aligntech.myinvisalign.emea component. This vulnerability, classified as CWE-321 (Use of Hard-coded Cryptographic Key), allows a local attacker to extract the token from the application's binary. According to external references, this token is associated with Contentful CDA, potentially granting unauthorized access to master and release environments. The attack requires local access to the device or the application package. As of the advisory date, the vendor has not responded to the disclosure, and no official patch has been confirmed.

Affected products

  • Align Technology My Invisalign App 3.12.4

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References