SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2026-18591

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android.

LOW 0.9EPSS 0.08%

Does this matter?

Lower severity and a low EPSS score (0.08%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The attack can be executed directly on the physical device. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CVSS 4.0
0.9 LOWCVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-310, CWE-312
Source
cna@vuldb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.