7.1
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H
Description
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
Basic Information
ID
CVE-2026-22070
Source
OPPO
Published
Apr 30, 2026 at 08:27
Affected Product
Vendor
OPPO
Product
ColorOS Assistant
Version
1.4.26