Home

Description

An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

PUBLISHED Reserved 2026-03-04 | Published 2026-04-01 | Updated 2026-04-01 | Assigner mitre

References

secsys.fudan.edu.cn/

play.google.com/store/apps/details?id=com.tinybeans

tinybeans.com/

github.com/Secsys-FDU/AF_CVEs/issues/17

cve.org (CVE-2026-30289)

nvd.nist.gov (CVE-2026-30289)

Download JSON