---
id: CVE-2026-89038
title: >-
  Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a
  path traversal vulnerability that allows co-resident malicious applications to
  write attacker-controlled bytes outside the intended staging directory by
  supplyi…
summary: >-
  Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a
  path traversal vulnerability that allows co-resident malicious applications to
  write attacker-controlled bytes outside the intended staging directory by
  supplyi…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-22
vendor: Verizon
product: com.vcast.mediamanager
affected:
  - com.vcast.mediamanager < 26.7.10
published: '2026-09-17'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:25:55.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89038'
references:
  - url: 'https://github.com/actuator/com.vcast.mediamanager'
    label: disclosure@vulncheck.com
  - url: 'https://play.google.com/store/apps/details?id=com.vcast.mediamanager'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/verizon-cloud-for-android-path-traversal-via-onetouchuploadactivity
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00189
epssPercentile: 0.07594
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:12:25.875847Z'
ingestedAt: '2026-09-17T18:25:16.050Z'
---

## Overview

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through exported activities OneTouchUploadActivity and PrintShopCloudActivity. Attackers can exploit the unsanitized filename concatenation in the file-staging sink via ACTION_SEND or ACTION_SEND_MULTIPLE intents to achieve arbitrary file write and inject attacker-controlled content into the authenticated user's Verizon Cloud account without user interaction.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
