{"id":"CVE-2026-89038","title":"Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…","summary":"Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-22"],"vendor":"Verizon","product":"com.vcast.mediamanager","affected":["com.vcast.mediamanager < 26.7.10"],"published":"2026-09-17","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:25:55.870","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89038","references":[{"url":"https://github.com/actuator/com.vcast.mediamanager","label":"disclosure@vulncheck.com"},{"url":"https://play.google.com/store/apps/details?id=com.vcast.mediamanager","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/verizon-cloud-for-android-path-traversal-via-onetouchuploadactivity","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00148,"epssPercentile":0.04424,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T19:12:25.875847Z"},"ingestedAt":"2026-09-17T18:25:16.050Z","slug":"CVE-2026-89038","body":"## Overview\n\nVerizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through exported activities OneTouchUploadActivity and PrintShopCloudActivity. Attackers can exploit the unsanitized filename concatenation in the file-staging sink via ACTION_SEND or ACTION_SEND_MULTIPLE intents to achieve arbitrary file write and inject attacker-controlled content into the authenticated user's Verizon Cloud account without user interaction.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":206580,"id":"CVE-2026-89038","ts":1789676942019,"field":"exploit_available","old":"false","new":"true"}]}