An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings.

Project Subscriptions

Vendors Products
Motorola Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update your Motorola Phone to software versions with a Security Patch Level of 2026-04-05 or later.


Workaround

No workaround given by the vendor.

History

Tue, 19 May 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 May 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Permission Escalation via Factory Test Component
Weaknesses CWE-284

Tue, 19 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings.
First Time appeared Motorola
Motorola phones
CPEs cpe:2.3:a:motorola:phones:*:*:*:*:*:*:*:*
Vendors & Products Motorola
Motorola phones
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-05-19T16:39:42.750Z

Reserved: 2026-04-08T14:38:14.415Z

Link: CVE-2026-5804

cve-icon Vulnrichment

Updated: 2026-05-19T16:38:20.549Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-19T16:16:22.413

Modified: 2026-05-19T17:57:25.143

Link: CVE-2026-5804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T18:00:12Z

Weaknesses