CVE-2026-4217 | XREAL Nebula App up to 3.2.1 on Android ai.nreal.nebula.universal CloudStoragePlugin.java accessKey/secretAccessKey/securityToken credentials storage
A vulnerability was found in XREAL Nebula App up to 3.2.1 on Android. It has been declared as problematic. This impacts an unknown function of the file in ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the component ai.nreal.nebula.universal. Such manipulation of the argument accessKey/secretAccessKey/securityToken leads to unprotected storage of credentials.
This vulnerability is referenced as CVE-2026-4217. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.