OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94204

HIGH · CVSS 7.5 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The misconfiguration of the central cloud storage backend for the dashcam platform allows public-read access, exposing sensitive user records, live dashcam footage, application packages, and firmware files to anyone on the internet. This vulnerability poses a significant risk to user privacy and data integrity, making it critical for organizations utilizing this dashcam platform to prioritize remediation efforts. Immediate action is essential to mitigate potential data breaches and protect user information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94204
Severity
HIGH
CVSS
7.5
EPSS
0.27%

Original NVD Description

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.