CVE-2026-94204

Élevée7.5Publiée le 29 septembre 2026

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

Score CVSS7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Type de faiblesse (CWE)CWE-732

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de données CVE