The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Viidure did not respond to CISA's coordination attempts. Users of affected versions of the Viidure Dashcam Android Application are advised to contact Viidure customer support for additional information https://viidure.app/. https://viidure.app/

History

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.
Title Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-29T21:02:00.018Z

Reserved: 2026-09-24T16:42:35.647Z

Link: CVE-2026-94204

cve-icon Vulnrichment

Updated: 2026-09-29T21:00:15.971Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T21:19:39.283

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-94204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses