Published:2026/10/06  Last Updated:2026/10/06

JVN#53292492
Multiple vulnerabilities in Android application "Ticket Ryutsu Center"

Overview

Android application "Ticket Ryutsu Center" provided by Wavedash Co., Ltd. contains multiple vulnerabilities.

Products Affected

  • Android application "Ticket Ryutsu Center" 4.1.9 and earlier

Description

Android application "Ticket Ryutsu Center" provided by Wavedash Co., Ltd. contains multiple vulnerabilities listed below:

  • Use of Hard-coded Credentials (CWE-798)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 5.1
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 4.0
    • CVE-2026-92861
  • Improper Authorization in Handler for Custom URL Scheme (CWE-939)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 4.6
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Base Score 3.3
    • CVE-2026-92862
    • In the CVSS assessment above, a victim user is tricked into installing a malicious application, the scenario assumes that the malicious application sends an intent to Android application "Ticket Ryutsu Center", causing a malicious website to be displayed in the application.

Impact

  • The hard-coded API key may be retrieved (CVE-2026-92861).
  • When an intent is received from a malicious application, an attacker may lead a user to access an arbitrary website via the vulnerable application. As a result, the user may become a victim of a phishing attack (CVE-2026-92862).

Solution

Update the Application
Update the application to the latest version according to the information provided by the developer.
The developer has released the following version in October 2025 that contains a fix for this vulnerability.

  • Android application "Ticket Ryutsu Center" 4.2.0
The developer states that the affected versions require the users to update the application immediately when invoked.
Regarding CVE-2026-92861, the hard-code the API key has been deleted from the latest version.
Also the vulnerable API key has been deactivated, therefore the information contained in the vulnerable application cannot be abused.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Koki Sato of BroadBand Security, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-92861
CVE-2026-92862
JVN iPedia JVNDB-2026-000145