Path Traversal Vulnerability in Verizon Cloud for Android
CVE-2026-89038
Key Information:
- Vendor
Verizon
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-89038?
Verizon Cloud for Android is affected by a path traversal vulnerability that allows malicious applications on the same device to write unauthorized data outside the designated staging directory. By manipulating the _display_name value with path traversal sequences, attackers can exploit exported activities, such as OneTouchUploadActivity and PrintShopCloudActivity, using ACTION_SEND or ACTION_SEND_MULTIPLE intents. This results in arbitrary file writes, enabling attackers to inject content into the user’s Verizon Cloud account without any interaction from the authenticated user.
Affected Version(s)
Verizon Cloud for Android 0 < 26.7.10
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
