CVE-2026-5454: Grid Organiser App
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file res/raw/app.json of the component co.gridapp.organiser. Performing a manipulation of the argument SegmentWriteKey results in use of hard-coded cryptographic key . The attack is only possible with local access. The exploit has been made public and could be used.
Affected products
- Grid Organiser App: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only
Published 2026-04-03. Last modified 2026-07-24.