CVE-2026-40000 is an improper access control vulnerability in ZTE File Manager. The exported Activity zte.com.cn.filer.FilePreViewActivity, which is intended to preview compressed files, can be launched by third-party applications that supply arbitrary file paths, including content URIs exposed through the application's file provider. Because the Activity processes attacker-controlled paths using the privilege context of ZTE File Manager, a local untrusted application can cause the app to open and expose files beyond the caller's normal sandbox permissions. On unrooted devices, this can permit reading files from restricted locations, including certain system directories such as /data/data and /data/local/tmp, subject to platform-enforced access restrictions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real Android local exploit PoC for CVE-2026-40000 targeting ZTE File Manager (package zte.com.cn.filer). The repo is centered on a small Android app named IntentLauncher that lets the user enter a file path or full content URI and then sends an explicit ACTION_VIEW intent to zte.com.cn.filer.FilePreViewActivity with FLAG_GRANT_READ_URI_PERMISSION. If the user enters a plain path, the app prepends content://zte.com.cn.filer.fileprovider/root_path/ and forces MIME type text/*. The exploit relies on the target app exposing FilePreViewActivity and internally using a FileProvider authority that maps broad filesystem paths, including root_path, allowing the target app to open attacker-chosen files using its own privileges. Repository structure: the main exploit logic is in IntentLauncher/app/src/main/java/com/example/intentlauncher/MainActivity.java; AndroidManifest.xml defines the launcher activity and a local FileProvider for the PoC app; activity_main.xml provides a minimal UI with a path input and a button; build.gradle/settings.gradle/gradlew/build.sh are standard Android build scaffolding. The README explains the vulnerability mechanics and exploitation flow in detail, including that ZTE File Manager may copy selected files into /sdcard/Android/data/zte.com.cn.filer/cache during preview/extract behavior, enabling practical file disclosure. This is not a remote exploit and contains no shellcode or post-exploitation payload; it is an operational local intent-abuse PoC that weaponizes Android inter-app communication against a vulnerable vendor file manager.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.