Junglewise Threat Intelligence

CVE-2026-5457: PropertyGuru AgentNet Singapore hard-coded keys in Android app

CVE-2026-5457 · Severity: low · CVSS 3.3 · Published 2026-04-03

Executive brief

The PropertyGuru AgentNet Singapore app for Android contains hard-coded security keys within its configuration files. This app is used by real estate agents to manage listings and client interactions. An attacker with local access to the device could potentially extract these keys to manipulate user profiles or inject unauthorized data into the platform's analytics services.

Technical details

A hard-coded cryptographic key vulnerability (CWE-321) exists in the PropertyGuru AgentNet Singapore App up to version 23.7.10 on Android. The flaw is located in the 'BuildConfig.java' file within the 'com.allproperty.android.agentnet' component, specifically involving the 'SEGMENT_ANDROID_WRITE_KEY' and 'SEGMENT_TOS_WRITE_KEY' arguments. An attacker with local access to the device can extract these hard-coded keys. This exposure can lead to unauthorized data injection and user profile manipulation via the Segment analytics platform. As of the advisory date, the vendor has not responded to the disclosure.

Affected products

  • PropertyGuru AgentNet Singapore App up to 23.7.10

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References