| CVE ID | CVE-2026-8990 |
| Publication date | 28 May 2026 |
| Vendor | View Concept |
| Product | Kidsview |
| Vulnerable versions | From 4.0.1 to 4.4.3 |
| Vulnerability type (CWE) | Authentication Bypass Using an Alternate Path or Channel (CWE-288) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Kidsview application and participated in coordination of its disclosure.
The vulnerability CVE-2026-8990: A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification.
This issue was fixed in version 4.4.3
Credits
We thank Jakub Lewandowski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.