# CVE-2026-8990

## Summary

- **CVE ID:** CVE-2026-8990
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-288, CWE-359
- **Published:** May 28, 2026
- **Last Modified:** May 28, 2026

## Description

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification.

This issue was fixed in version 4.4.3

## Affected Products

- View Concept — Kidsview (4.0.1)

## References

- [CNA](https://cert.pl/posts/2026/05/CVE-2026-8990)
- [CNA](https://kidsview.pl/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._