CVE-2026-5804
HIGH
NVD
CVSS Score
8.4
Severity
HIGH
Published
May 19, 2026
Vendor
unknown
Description
An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external storage which could be used by third party apps running on the device to open a TCP server, exposing sensitive permissions and data. This could allow a local attacker to bypass permission checks and access protected device settings.