Junglewise Threat Intelligence

CVE-2026-86701: ManabiPocket for Parents improper access control vulnerability

CVE-2026-86701 · Severity: low · CVSS 2.5 · Published 2026-09-15

Executive brief

ManabiPocket for Parents is an Android parental monitoring application used to track student activity and attendance. The app contains an improper access control vulnerability that allows malicious applications already installed on a user's device to intercept and steal session information through Android Intents, potentially enabling account takeover by an attacker impersonating the legitimate user.

Technical details

The vulnerability is an improper export of Android application components (CWE-926) where sensitive components are not properly protected from inter-application communication. A malicious application installed on the same Android device can invoke the affected component via an Intent to extract session information. Exploitation requires the malicious app to be pre-installed on the device; it does not require user interaction or elevated permissions. An attacker can obtain the authenticated user's session credentials and impersonate that user to access the service. The vendor has patched this issue in version 1.2.4.

Affected products

  • NTT DOCOMO BUSINESS ManabiPocket for Parents 1.2.3 and earlier

Timeline

  • 2026-09-15: disclosed
  • 2026-09-11: patched: Version 1.2.4 released with fix

References