CVE-2026-30290: Intouchapp Intouch Contacts & Caller Id

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Affected products

  • Intouchapp Intouch Contacts & Caller Id: version 6.38.1 only

Published 2026-03-31. Last modified 2026-07-24.