CVE-2026-5452: Ucc Campusconnect App

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This manipulation causes use of hard-coded cryptographic key . The attack can only be executed locally. The exploit has been published and may be used.

Affected products

  • Ucc Campusconnect App: version 14.3.0 only; version 14.3.1 only; version 14.3.2 only; version 14.3.3 only; version 14.3.4 only; version 14.3.5 only

Published 2026-04-03. Last modified 2026-07-24.