CVE-2026-47364: Datadog Android App

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems.

Affected products

  • Datadog Android App: before 5.9.2 (fixed in 5.9.2)

Published 2026-08-07. Last modified 2026-09-03.