Post

CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application

CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application

CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application

CVE-2026-94204 highlights a critical vulnerability in the Viidure Dashcam Android Application. The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. 🚨 This misconfiguration exposes sensitive user records, live dashcam footage, application packages, and firmware files to anyone on the internet.

Key Details:

  • Published Date: September 29, 2026, at 9:19 p.m.
  • Last Modified: September 29, 2026, at 10:19 p.m.
  • Exploitability: Remotely exploitable.

Affected Products:

While specific affected products have not been recorded, the vulnerability impacts the entire platform due to its shared storage nature.

Associated Vulnerabilities:

CVE-2026-94204 is linked to CWE-732: Incorrect Permission Assignment for Critical Resource. Additionally, it is associated with various CAPECs, including:

  • CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
  • CAPEC-17: Using Malicious Files
  • CAPEC-60: Reusing Session IDs (aka Session Replay)
  • CAPEC-61: Session Fixation
  • CAPEC-62: Cross Site Request Forgery
  • CAPEC-122: Privilege Abuse
  • CAPEC-127: Directory Indexing
  • CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels
  • CAPEC-206: Signing Malicious Code

To mitigate this vulnerability, organizations should:

  • Remove public-read permissions from the cloud storage bucket.
  • Implement strict access controls for sensitive data.
  • Review and secure all stored objects.
  • Regularly audit storage configurations.

For more details, you can read the complete article here: Read full article

This post is licensed under CC BY 4.0 by the author.