CVE-2026-47364

Summary

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out.

Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems.

Affected Software

VendorProductVersion RangeStatus
DatadogAndroid App5.9.2 < 5.9.2affected

Weaknesses

  • CWE-200: CWE-200 Information Disclosure

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References