๐Ÿ” CVE Alert

CVE-2026-89038

MEDIUM 6.2

Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
0th

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through exported activities OneTouchUploadActivity and PrintShopCloudActivity. Attackers can exploit the unsanitized filename concatenation in the file-staging sink via ACTION_SEND or ACTION_SEND_MULTIPLE intents to achieve arbitrary file write and inject attacker-controlled content into the authenticated user's Verizon Cloud account without user interaction.

CWE CWE-22
Vendor verizon
Product verizon cloud for android
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for verizon verizon cloud for android

Be the first to know when new medium vulnerabilities affecting verizon verizon cloud for android are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Verizon / Verizon Cloud for Android
0 < 26.7.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/actuator/com.vcast.mediamanager play.google.com: https://play.google.com/store/apps/details?id=com.vcast.mediamanager vulncheck.com: https://www.vulncheck.com/advisories/verizon-cloud-for-android-path-traversal-via-onetouchuploadactivity

Credits

Edward "Actuator" Warren VulnCheck