CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application
CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application
CVE-2026-94204 highlights a critical vulnerability in the Viidure Dashcam Android Application. The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. 🚨 This misconfiguration exposes sensitive user records, live dashcam footage, application packages, and firmware files to anyone on the internet.
Key Details:
- Published Date: September 29, 2026, at 9:19 p.m.
- Last Modified: September 29, 2026, at 10:19 p.m.
- Exploitability: Remotely exploitable.
Affected Products:
While specific affected products have not been recorded, the vulnerability impacts the entire platform due to its shared storage nature.
Associated Vulnerabilities:
CVE-2026-94204 is linked to CWE-732: Incorrect Permission Assignment for Critical Resource. Additionally, it is associated with various CAPECs, including:
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
- CAPEC-17: Using Malicious Files
- CAPEC-60: Reusing Session IDs (aka Session Replay)
- CAPEC-61: Session Fixation
- CAPEC-62: Cross Site Request Forgery
- CAPEC-122: Privilege Abuse
- CAPEC-127: Directory Indexing
- CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels
- CAPEC-206: Signing Malicious Code
Recommended Solutions:
To mitigate this vulnerability, organizations should:
- Remove public-read permissions from the cloud storage bucket.
- Implement strict access controls for sensitive data.
- Review and secure all stored objects.
- Regularly audit storage configurations.
For more details, you can read the complete article here: Read full article