VORANT. Threat Intelligence Sign in Get the full feed

Kidsview App Authentication Bypass Patched

low vulnerability

A vulnerability in the Kidsview mobile app let someone with physical device access bypass login and take over the account via push notifications; fixed in version 4.4.3.

CERT Polska coordinated disclosure of CVE-2026-8990, a vulnerability affecting the Kidsview mobile application. The flaw allows an attacker with physical access to a victim's smartphone to bypass the app's authentication mechanism by interacting with a push notification, granting themselves full access to the device owner's account.

The vulnerability requires local physical access rather than remote exploitation, limiting its scale but still posing a risk to users in scenarios such as device theft, loss, or shared access. The issue has been fixed in Kidsview version 4.4.3, and users are advised to update. The report was credited to researcher Jakub Lewandowski through CERT Polska's coordinated vulnerability disclosure process.

Mentioned in this report

Vulnerabilities CVE-2026-8990

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8990

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free