Path Traversal Vulnerability in Verizon Cloud for Android
CVE-2026-89038

6.9MEDIUM

Key Information:

Vendor

Verizon

Vendor
CVE Published:
17 September 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-89038?

Verizon Cloud for Android is affected by a path traversal vulnerability that allows malicious applications on the same device to write unauthorized data outside the designated staging directory. By manipulating the _display_name value with path traversal sequences, attackers can exploit exported activities, such as OneTouchUploadActivity and PrintShopCloudActivity, using ACTION_SEND or ACTION_SEND_MULTIPLE intents. This results in arbitrary file writes, enabling attackers to inject content into the user’s Verizon Cloud account without any interaction from the authenticated user.

Affected Version(s)

Verizon Cloud for Android 0 < 26.7.10

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edward "Actuator" Warren
VulnCheck
.