CVE-2026-47362: Datadog Android App
Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.
In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history). Impact: Any actor able to bypass the app sandbox can read these databases in plaintext.
Affected products
- Datadog Android App: before 5.9.4 (fixed in 5.9.4)
Published 2026-08-07. Last modified 2026-09-03.