CVE-2026-82988: Malicious File Upload
Published Oct 5, 2026
·Updated
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint
Affected Software
1 affected component
ViewSonic ViewBoard
Event History
Oct 5, 2026
CVE Published
via MITRE·11:14 PM
Data Sourced
via MITRE·11:14 PM
DescriptionWeakness
Oct 6, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are exposed to this issue?
ViewSonic ViewBoard systems using the vCast APK delivery mechanism are the affected product scope described in the available information.
2
What does an attacker need to exploit it?
An attacker can act remotely and does not need to authenticate. Exploitation involves providing a malicious APK URL through an unauthenticated download endpoint.
3
What is the immediate impact of successful exploitation?
Successful exploitation can cause an unprivileged APK to be installed on the targeted ViewBoard.