CVE-2026-94204

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-29: 209-29
Referenced assets1 URL
By indicator
Full discourse2 posts
  • NewsTongue@NewsTongueX

    🔴 Viidure dashcam app leaks cloud credentials, user data exposed worldwide Viidure Dashcam Android Application versions <=3.3.1.260403 contain two critical vulnerabilities (CVE-2026-94204, CVE-2026-96587) that expose sensitive user data and system files to unauthenticated internet access. The cloud storage backend is misconfigured with public-read permissions, allowing unrestricted access to dashcam footage, user records, application packages, and firmware.

    0000037
    930 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — VIIDURE DASHCAM ANDROID APP: TWO CVSS 10 FLAWS INCLUDE HARD-CODED CREDENTIALS AND CAN EXPOSE SENSITIVE DATA AND CRITICAL SYSTEM FILES September 29, 2026 DISCLOSED BY: CISA ICS PRODUCT: Viidure Dashcam Android Application CVE: CVE-2026-94204 CVE-2026-96587 IMPACT: Incorrect permission assignment for critical resources and use of hard-coded credentials. CISA states successful exploitation could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the wider platform. CVSS: 10.0 Critical EXPLOITATION STATUS: VULNERABILITIES CONFIRMED NO CONFIRMED IN-THE-WILD EXPLOITATION IDENTIFIED Accuracy note: Hard-coded credentials are a serious credential/security-design flaw, but this advisory does not establish an active credential-theft or phishing campaign. URGENT ACTION: Stop using affected builds or upgrade to vendor-fixed releases when available. Review application permissions and associated credentials and investigate unexpected access to user data or critical files. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07 #CyberSecurity #ThreatIntel #Viidure #AndroidSecurity #HardcodedCredentials #MobileSecurity #CVE

    0000039
    225 followersView on X

Explore more