CVE-2026-94204: Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application
The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable public-read permissions on the shared storage bucket so stored objects are not accessible to anyone on the internet.
Central cloud storage bucket Public-read permissions = disabled
Event History
Frequently Asked Questions
Does an attacker need a Viidure account or any special access to retrieve the exposed data?
No. The storage backend permits public read access, so anyone on the internet can access stored objects without authentication.
What kinds of assets may be accessible through the misconfigured storage backend?
The exposed shared storage may contain sensitive user records, live dashcam footage, Android application packages, and firmware files.