# Kidsview App Authentication Bypass Patched

Published: 2026-05-28 · Severity: low
Canonical: https://vorant.io/reports/a6ad58f4-7797-54d9-bc3d-c3da05bda925/kidsview-app-authentication-bypass-patched

> A vulnerability in the Kidsview mobile app let someone with physical device access bypass login and take over the account via push notifications; fixed in version 4.4.3.

CERT Polska coordinated disclosure of CVE-2026-8990, a vulnerability affecting the Kidsview mobile application. The flaw allows an attacker with physical access to a victim's smartphone to bypass the app's authentication mechanism by interacting with a push notification, granting themselves full access to the device owner's account.

The vulnerability requires local physical access rather than remote exploitation, limiting its scale but still posing a risk to users in scenarios such as device theft, loss, or shared access. The issue has been fixed in Kidsview version 4.4.3, and users are advised to update. The report was credited to researcher Jakub Lewandowski through CERT Polska's coordinated vulnerability disclosure process.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8990

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8990

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a6ad58f4-7797-54d9-bc3d-c3da05bda925/kidsview-app-authentication-bypass-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
