Published:2026/09/15  Last Updated:2026/09/15

JVN#72918755
Improper access control vulnerability in Android application "ManabiPocket for Parents"

Overview

Android application "ManabiPocket for Parents" provided by NTT DOCOMO BUSINESS, Inc. contains an improper access control vulnerability.

Products Affected

  • Android application "ManabiPocket for Parents" versions 1.2.3 and earlier

Description

Android application "ManabiPocket for Parents" provided by NTT DOCOMO BUSINESS, Inc. contains the following vulnerability:

  • Improper Export of Android Application Components (CWE-926)
    • CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 1.8
    • CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Base Score 2.5
    • CVE-2026-86701
    • The CVSS above assumes that sensitive information within the affected application is obtained by a malicious application installed on the device via an Intent.

Impact

A malicious application installed on the device may obtain sensitive information from the affected application via an Intent.

Solution

Update the application
Update the application to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Yuta Sasaki of Ai Solutions Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-86701
JVN iPedia JVNDB-2026-000136