VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
2026-09-25T20:52:03Z•7f2e0727776337f80f218c2bc8f70e55098ea5b485caf0951e1385d6d3b9b4ea
CVE-2026-18311CVE-2026-18312CVE-2026-75907CVE-2026-82356CVE-2026-82987CVE-2026-82988CVE-2026-82989CVE-2026-86867AndroidIoTOS-command-injectionRFIDSecure-Boot-bypassUEFIWebViewXSSaccess-controlarbitrary-APK-installationbroken-access-controlcertificate-impersonationcross-site-scriptingcryptographic-key-managementdevice-compromiseenterprise-securityhealthcareimproper-authenticationkey-rotationmulti-tenant-isolationroot-code-executionscreen-captureunauthenticated-access
What happened
CERT/CC advisories disclose multiple serious vulnerabilities: stored XSS in Readwise Reader for Android; unauthenticated screen exfiltration, arbitrary APK installation, and input injection in ViewSonic vCast; replayable RFID credentials in Norwegian Cruise Line door controllers; non-rotatable RSA keys in Imprivata EAM; cross-user conversation access in Kotaemon; Secure Boot bypass via vendor-signed UEFI Shell applications; and authenticated root-level OS command injection in Dokploy. Several issues enable unauthorized data access, persistence, arbitrary code execution, or physical access.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 7f2e0727776337f80f218c2bc8f70e55098ea5b485caf0951e1385d6d3b9b4ea
- Enrichment time
- 2026-09-25T20:52:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.