Misconfigured Cloud Storage Leading to Data Exposure in Dashcam Platform
CVE-2026-94204

8.7HIGH

Key Information:

Vendor

Viidure

Vendor
CVE Published:
29 September 2026

What is CVE-2026-94204?

The cloud storage backend for the dashcam platform is improperly configured with public-read permissions, resulting in a significant security flaw. This misconfiguration allows anyone on the internet to access sensitive user data, including personal records, live dashcam footage, application packages, and firmware files. The implications of this vulnerability extend to potential unauthorized use of personal information and privacy violations for all users of the platform.

Affected Version(s)

Dashcam Android Application 0 <= 3.3.1.260403

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bugrahan Karahan
.