CVE-2026-96587
Awaiting Analysis Awaiting Analysis - Queue

Permanent Plaintext Credentials in Viidure Android App

Vulnerability report for CVE-2026-96587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: ICS-CERT

Description

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Viidure Android app storing cloud storage credentials in plaintext within its compiled code. These credentials grant full access to platform storage, allowing unauthorized users to read, modify, or delete critical files like firmware and application binaries.

Detection Guidance

This vulnerability involves hardcoded cloud storage credentials in the Viidure Android application. To detect it, inspect the application's compiled code or decompiled APK for plaintext credentials using tools like apktool, jadx, or strings command. Search for keywords like 'access_key', 'secret_key', or 'cloud storage' in the code.

Impact Analysis

Attackers could exploit this to access and manipulate sensitive data, disrupt services, or install malicious firmware. Users may face data breaches, system failures, or unauthorized control over their devices and cloud storage.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized data access and HIPAA if it exposes protected health information. Organizations could face legal penalties, fines, and reputational damage for failing to protect sensitive data.

Mitigation Strategies

Immediately remove the Viidure Android application from all devices. Rotate all cloud storage credentials associated with the application. Contact the vendor for a patched version. Monitor network traffic for unauthorized access to cloud storage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart