CVE-2026-22070
·
NIST NVD ↗
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
HIGH
CVSS severity
7.1
CVSS base score
2026-04-30
Published
CWE codes
CWE-23
CWE-22
Affected products
oppo:coloros_assistant
Sources
NIST NVD:
https://nvd.nist.gov/vuln/detail/CVE-2026-22070