CVE-2026-96587

Critical10.0Published on September 29, 2026

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

CVSS score10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness type (CWE)CWE-798

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database