{"id":"CVE-2026-96587","title":"The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code","summary":"The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operatio…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-798"],"vendor":"Viidure","product":"Dashcam Android Application","affected":["dashcam_android_application <= 3.3.1.260403"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T22:19:05.860","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96587","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://viidure.app/","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07","label":"ics-cert@hq.dhs.gov"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-29T20:54:54.814937Z"},"ingestedAt":"2026-09-29T21:49:08.218Z","slug":"CVE-2026-96587","body":"## Overview\n\nThe Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}