Description
A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the file campusconnect/BuildConfig.java of the component campusconnect.ucc. This manipulation causes use of hard-coded cryptographic key . The attack can only be executed locally. The exploit has been published and may be used.
Problem types
Use of Hard-coded Cryptographic Key
Product status
14.3.1
14.3.2
14.3.3
14.3.4
14.3.5
Timeline
| 2026-04-02: | VulDB entry created |
| 2026-04-03: | Advisory disclosed |
| 2026-04-03: | VulDB entry last update |
Credits
fxizenta (VulDB User)
References
vuldb.com/vuln/355040 (VDB-355040 | UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key)
vuldb.com/vuln/355040/cti (VDB-355040 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/781757 (Submit #781757 | CampusConnect™ UCC CampusConnect(campusconnect.ucc) 14.3.5 Uploadcare Private Key Exposure)
www.notion.so/...3f97fb8057bc67ec4320672d99?source=copy_link