CriticalCritical vulnerability
CVE-2026-96587 (CVSS 10.0)
NVD · officialPublished Sep 29, 2026Risk 50/100
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
Technical details
CVSS
10.0
AV:NetworkAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source