VORANT. Threat Intelligence Sign in Get the full feed

Kidsview mobile app CVE-2026-8990 allows physical attackers to bypass authentication via…

medium vulnerability

Kidsview mobile app CVE-2026-8990 allows physical attackers to bypass authentication via push notification interaction, fixed in version 4.4.3.

CERT Polska coordinated disclosure of CVE-2026-8990, an authentication bypass vulnerability in the Kidsview mobile application. An attacker with physical access to a smartphone can interact with the application's push notifications to bypass authentication controls and gain full access to the device owner's account. This vulnerability requires local access to the device, limiting its exploitability to scenarios where an adversary has physical possession of or proximity to the victim's smartphone.

The vulnerability was responsibly reported by security researcher Jakub Lewandowski and has been remediated by the vendor in Kidsview version 4.4.3. Users of the application should update to this version or later to eliminate the exposure.

While the attack vector requires physical access rather than remote exploitation, the complete authentication bypass represents a significant privacy and security risk for application users, particularly given Kidsview's nature as a parental control and monitoring solution.

Mentioned in this report

Vulnerabilities CVE-2026-8990

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8990

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free