CVE-2026-22070

· NIST NVD ↗

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

HIGH
CVSS severity
7.1
CVSS base score
2026-04-30
Published

CWE codes

CWE-23CWE-22

Affected products

oppo:coloros_assistant

Sources