# Kidsview mobile app CVE-2026-8990 allows physical attackers to bypass authentication via…

Published: 2026-05-28 · Severity: medium
Canonical: https://vorant.io/reports/accaf138-6895-4322-9ab4-884475fdacc6/kidsview-mobile-app-cve-2026-8990-allows-physical-attackers-to-bypass

> Kidsview mobile app CVE-2026-8990 allows physical attackers to bypass authentication via push notification interaction, fixed in version 4.4.3.

CERT Polska coordinated disclosure of CVE-2026-8990, an authentication bypass vulnerability in the Kidsview mobile application. An attacker with physical access to a smartphone can interact with the application's push notifications to bypass authentication controls and gain full access to the device owner's account. This vulnerability requires local access to the device, limiting its exploitability to scenarios where an adversary has physical possession of or proximity to the victim's smartphone.

The vulnerability was responsibly reported by security researcher Jakub Lewandowski and has been remediated by the vendor in Kidsview version 4.4.3. Users of the application should update to this version or later to eliminate the exposure.

While the attack vector requires physical access rather than remote exploitation, the complete authentication bypass represents a significant privacy and security risk for application users, particularly given Kidsview's nature as a parental control and monitoring solution.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8990

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8990

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/accaf138-6895-4322-9ab4-884475fdacc6/kidsview-mobile-app-cve-2026-8990-allows-physical-attackers-to-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
