Junglewise Threat Intelligence

CVE-2026-8990: View Concept Kidsview authentication bypass via push notifications

CVE-2026-8990 · Severity: info · CVSS 5.3 · Published 2026-05-28

Executive brief

Kidsview is a mobile application used by parents, teachers, and school administrators to manage childcare activities, attendance, and payments. A security flaw allows a person with physical access to a user's smartphone to bypass the app's authentication and gain full access to the account by interacting with push notifications. This could lead to the unauthorized viewing of sensitive student data, personal information, or financial records.

Technical details

An authentication bypass vulnerability (CWE-288) exists in the Kidsview mobile application for versions 4.0.1 through 4.4.2. The flaw resides in the handling of push notifications, where an unauthorized user with physical access to the smartphone can bypass the application's primary authentication mechanism (such as a PIN or biometric lock) by interacting with a notification. This grants the attacker full access to the device owner's account, potentially exposing private personal information (CWE-359). The issue has been addressed in version 4.4.3.

Affected products

  • View Concept Kidsview 4.0.1 to 4.4.2

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory
  • 2026-05-28: patched: Fixed in version 4.4.3

References