CVE-2026-72506
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-941
- Published
- 2026-08-13
- Last modified
- 2026-08-13
Affected products
- National Institute of Information and Communications Technology "VoiceTra(Voice Translator)" for Android
- National Institute of Information and Communications Technology "VoiceTra(Voice Translator)" for iOS
Weakness type
Related vulnerabilities
- CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks
- CVE-2026-40118 — UDP Console provided by Arcserve contains an incorrectly specified destination in a communication...
- CVE-2025-53899 — Kiteworks MFT is vulnerable to an Incorrectly Specified Destination in a Communication Channel
- CVE-2025-0036 — In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime...
- CVE-2023-33198 — Incorrectly Specified Chat Message Destinations in tgstation-server and DreamMaker API
- CVE-2022-4847 — Incorrectly Specified Destination in a Communication Channel in usememos/memos
- CVE-2019-18242 — In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility,...