Published:2026/09/15 Last Updated:2026/09/15
JVN#72918755
Improper access control vulnerability in Android application "ManabiPocket for Parents"
Overview
Android application "ManabiPocket for Parents" provided by NTT DOCOMO BUSINESS, Inc. contains an improper access control vulnerability.
Products Affected
- Android application "ManabiPocket for Parents" versions 1.2.3 and earlier
Description
Android application "ManabiPocket for Parents" provided by NTT DOCOMO BUSINESS, Inc. contains the following vulnerability:
- Improper Export of Android Application Components (CWE-926)
- CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 1.8
- CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Base Score 2.5
- CVE-2026-86701
- The CVSS above assumes that sensitive information within the affected application is obtained by a malicious application installed on the device via an Intent.
Impact
A malicious application installed on the device may obtain sensitive information from the affected application via an Intent.
Solution
Update the application
Update the application to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| NTT DOCOMO BUSINESS, Inc. | Request to Update “Manabi Pocket for Parents” Following a Security Fix (For Android Users) (Text in Japanese) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Yuta Sasaki of Ai Solutions Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-86701 |
| JVN iPedia |
JVNDB-2026-000136 |