Published:2026/10/06 Last Updated:2026/10/06
JVN#53292492
Multiple vulnerabilities in Android application "Ticket Ryutsu Center"
Overview
Android application "Ticket Ryutsu Center" provided by Wavedash Co., Ltd. contains multiple vulnerabilities.
Products Affected
- Android application "Ticket Ryutsu Center" 4.1.9 and earlier
Description
Android application "Ticket Ryutsu Center" provided by Wavedash Co., Ltd. contains multiple vulnerabilities listed below:
- Use of Hard-coded Credentials (CWE-798)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 5.1
- CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 4.0
- CVE-2026-92861
- Improper Authorization in Handler for Custom URL Scheme (CWE-939)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 4.6
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Base Score 3.3
- CVE-2026-92862
- In the CVSS assessment above, a victim user is tricked into installing a malicious application, the scenario assumes that the malicious application sends an intent to Android application "Ticket Ryutsu Center", causing a malicious website to be displayed in the application.
Impact
- The hard-coded API key may be retrieved (CVE-2026-92861).
- When an intent is received from a malicious application, an attacker may lead a user to access an arbitrary website via the vulnerable application. As a result, the user may become a victim of a phishing attack (CVE-2026-92862).
Solution
Update the Application
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version in October 2025 that contains a fix for this vulnerability.
- Android application "Ticket Ryutsu Center" 4.2.0
Regarding CVE-2026-92861, the hard-code the API key has been deleted from the latest version.
Also the vulnerable API key has been deactivated, therefore the information contained in the vulnerable application cannot be abused.
Vendor Status
| Vendor | Link |
| Wavedash Co., Ltd. | Ticket Ryutsu Center Android application (Text in Japanese) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Koki Sato of BroadBand Security, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-92861 |
|
CVE-2026-92862 |
|
| JVN iPedia |
JVNDB-2026-000145 |