Description
Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through exported activities OneTouchUploadActivity and PrintShopCloudActivity. Attackers can exploit the unsanitized filename concatenation in the file-staging sink via ACTION_SEND or ACTION_SEND_MULTIPLE intents to achieve arbitrary file write and inject attacker-controlled content into the authenticated user's Verizon Cloud account without user interaction.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write and Unauthorized Content Injection
Action: Immediate Patch
AI Analysis

Impact

Verizon Cloud for Android (com.vcast.mediamanager) before version 26.7.10 has a path traversal flaw that lets a co‑resident malicious application supply a crafted _display_name value containing path‑traversal sequences. The flaw exists in the exported activities OneTouchUploadActivity and PrintShopCloudActivity and is triggered via ACTION_SEND or ACTION_SEND_MULTIPLE intents. Because the filename is concatenated without sanitization, an attacker can write arbitrary bytes to locations outside the intended staging directory and inject attacker‑controlled content directly into the authenticated user’s Verizon Cloud account, all without user interaction.

Affected Systems

Verizon Cloud for Android, version 26.7.10 and earlier. The affected application package is com.vcast.mediamanager. Users running any pre‑26.7.10 build are vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity vulnerability, while the EPSS value of less than 1% suggests a low probability of exploitation at the current time. The flaw is not listed in the CISA KEV catalog. Exploitation requires a malicious co‑resident app to target the exported upload activities; no user‑initiated interaction is needed beyond installing the attacker’s application or sending a crafted intent. This local attack surface limits the attack to devices where the attacker can install an app, but once present, it allows arbitrary file write that bypasses permission controls.

Generated by OpenCVE AI on September 19, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Verizon Cloud for Android to version 26.7.10 or later, which removes the unsanitized _display_name handling.
  • Modify or remove the exported intent filters for OneTouchUploadActivity and PrintShopCloudActivity so only signed or system apps can access them, preventing other apps from invoking the vulnerable behavior.
  • Enforce device security policies that restrict installation of untrusted applications or use app‑level sandboxing to prevent co‑resident apps from exercising this permission.

Generated by OpenCVE AI on September 19, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Verizon
Verizon verizon Cloud For Android
Vendors & Products Verizon
Verizon verizon Cloud For Android

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplying a crafted _display_name value containing path-traversal sequences through exported activities OneTouchUploadActivity and PrintShopCloudActivity. Attackers can exploit the unsanitized filename concatenation in the file-staging sink via ACTION_SEND or ACTION_SEND_MULTIPLE intents to achieve arbitrary file write and inject attacker-controlled content into the authenticated user's Verizon Cloud account without user interaction.
Title Verizon Cloud for Android < 26.7.10 Path Traversal via OneTouchUploadActivity
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Verizon Verizon Cloud For Android
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:13:05.703Z

Reserved: 2026-09-10T16:23:54.473Z

Link: CVE-2026-89038

cve-icon Vulnrichment

Updated: 2026-09-17T19:12:58.667Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T18:17:13.983

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-89038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')