---
id: CVE-2026-94204
title: >-
  The central cloud storage backend for the entire dashcam platform is
  misconfigured with public-read permissions, allowing unrestricted access to
  all stored objects
summary: >-
  The central cloud storage backend for the entire dashcam platform is
  misconfigured with public-read permissions, allowing unrestricted access to
  all stored objects. Because this bucket serves as shared storage for the
  platform, sensitive…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-732
vendor: Viidure
product: Dashcam Android Application
affected:
  - dashcam_android_application <= 3.3.1.260403
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T22:19:03.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94204'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-07.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://viidure.app/'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-07'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-29T20:55:08.569132Z'
ingestedAt: '2026-09-29T21:49:08.218Z'
---

## Overview

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
