Junglewise Threat Intelligence

CVE-2026-5458: Noelse Individuals & Pro App hard-coded key in BuildConfig

CVE-2026-5458 · Severity: low · CVSS 3.3 · Published 2026-04-03

Executive brief

Noelse Individuals & Pro is a financial services application for Android. A security flaw in the app's code includes a hard-coded cryptographic key, which could allow a local attacker or malicious app on the same device to access sensitive data or manipulate user profiles. This could lead to unauthorized data injection and potential compromise of user account information.

Technical details

A vulnerability exists in the Noelse Individuals & Pro App (com.afone.noelse) up to version 2.1.7 on Android due to the use of a hard-coded cryptographic key. Specifically, the 'SEGMENT_WRITE_KEY' argument within the 'com/reactnative/antelop/BuildConfig.java' file is statically defined. A local attacker with low privileges can exploit this to perform data injection or manipulate user profiles within the Segment analytics framework integrated into the app. While the vendor was notified, no patch has been confirmed at the time of disclosure, and a proof-of-concept exploit is publicly available.

Affected products

  • Noelse Individuals & Pro App up to 2.1.7

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References