CVE-2026-8990
Deferred
Deferred - Pending Action
Authentication Bypass in Kidsview Mobile App via Push Notifications
Publication date: 2026-05-28
Last updated on: 2026-05-28
Assigner: CERT.PL
Description
Description
A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification.
This issue was fixed in version 4.4.3
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| kidsview | kidsview | 4.4.3 |
| kidsview | kidsview | to 4.4.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-359 | The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected. |
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |