PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8990 View Concept CVE debrief

A physical-access authentication bypass vulnerability in the Kidsview mobile application allows an attacker with physical access to a smartphone to bypass authentication and gain full access to the device owner's account by interacting with the application's push notification. The vulnerability was fixed in version 4.4.3. The issue involves weaknesses in authentication mechanism implementation (CWE-288) and exposure of sensitive information to an unauthorized actor (CWE-359). The CVSS 4.0 vector indicates physical attack vector with high confidentiality and integrity impact.

Vendor
View Concept
Product
Kidsview
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-28
Advisory published
2026-05-28
Advisory updated
2026-05-28

Who should care

Organizations and individuals using the Kidsview mobile application for parental control or device monitoring, particularly those with devices that may be accessible to unauthorized users. Mobile application security teams and developers implementing push notification-based authentication flows.

Technical summary

The Kidsview mobile application contains an authentication bypass vulnerability where an attacker with physical access to a smartphone can interact with the application's push notification to grant themselves full access to the device owner's account. The vulnerability stems from improper authentication mechanism implementation (CWE-288) and potential exposure of sensitive information through push notifications (CWE-359). The attack requires physical access to the device (AV:P) and has high impact on confidentiality and integrity. The vendor has released version 4.4.3 containing the security fix.

Defensive priority

medium

Recommended defensive actions

  • Update Kidsview mobile application to version 4.4.3 or later to remediate the authentication bypass vulnerability
  • Implement additional authentication controls for push notification interactions to prevent unauthorized account access
  • Review and strengthen authentication mechanisms in mobile applications to address CWE-288 (Authentication Bypass Issues)
  • Assess exposure of sensitive information in push notifications to address CWE-359 (Exposure of Private Information)
  • Monitor for unauthorized access attempts on devices running affected versions of Kidsview
  • Apply device-level security controls (screen lock, biometric authentication) to complement application-level fixes

Evidence notes

CVE published 2026-05-28T14:16:25.170Z; modified 2026-05-28T18:00:22.543Z. Fix version 4.4.3 confirmed in CVE description. CERT.PL advisory and vendor website referenced as sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8990 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8990

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8990 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8990

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.