CVE-2026-8990

MEDIUM

Authentication Bypass in Kidsview

Title source: cna
STIX 2.1

Description

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/05/CVE-2026-8990
Product product
https://kidsview.pl/

Scores

CVSS v4 5.3
EPSS 0.0021
EPSS Percentile 10.8%
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-288 CWE-359
Status published
Products (1)
View Concept/Kidsview 4.0.1 - 4.4.3
Published May 28, 2026
Tracked Since May 28, 2026