CVE-2026-5453 | Rico só vantagem pra investir App up to 4.58.32.12421 on Android br.com.rico.mobile SegmentSettingsModule.java SEGMENT_WRITE_KEY hard-coded key (EUVD-2026-18597)
A vulnerability classified as problematic was found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects some unknown processing of the file br/com/rico/mobile/di/SegmentSettingsModule.java of the component br.com.rico.mobile. Such manipulation of the argument SEGMENT_WRITE_KEY leads to use of hard-coded cryptographic key
.
This vulnerability is referenced as CVE-2026-5453. The attack can only be performed from a local environment. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.