CVE-2026-72506

Summary

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

Affected Software

VendorProductVersion RangeStatus
National Institute of Information and Communications Technology“VoiceTra(Voice Translator)” for Android9.1.3 <= 9.2.0affected
National Institute of Information and Communications Technology“VoiceTra(Voice Translator)” for iOS9.1.3 <= 9.2.0affected

Weaknesses

  • CWE-941: Incorrectly specified destination in a communication channel

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References