PT-2026-95024 · Verizon · Verizon Cloud

·

CVE-2026-89038

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Verizon Cloud for Android versions prior to 26.7.10
Description A path traversal issue exists where co-resident malicious applications can write attacker-controlled bytes outside the intended staging directory. This occurs due to unsanitized filename concatenation in the file-staging sink when processing ACTION SEND or ACTION SEND MULTIPLE intents. An attacker can supply a crafted display name value containing path-traversal sequences through the exported activities OneTouchUploadActivity and PrintShopCloudActivity to achieve arbitrary file write and inject content into the authenticated user's account without user interaction.
Recommendations Update to version 26.7.10 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89038

Affected Products

Verizon Cloud