


Perceptive Security
SOC/SIEM Consultancy

An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file i…
Published:
31 March 2026 at 22:00:00
Alert date:
1 April 2026 at 18:02:24
Source:
nvd.nist.gov
Mobile & IoT
CVE-2026-30289 is an arbitrary file overwrite vulnerability in Tinybeans Private Family Album App version 5.9.5-prod. The vulnerability allows attackers to overwrite critical internal files through the file import process. This can lead to arbitrary code execution or information exposure. The vulnerability affects the mobile application used for private family photo sharing. The issue represents a significant security risk given the potential for code execution and data exposure.
Technical details
Mitigation steps:
Affected products:
Tinybeans Private Family Album App
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30289
https://github.com/Secsys-FDU/AF_CVEs/issues/17
https://play.google.com/store/apps/details?id=com.tinybeans
https://secsys.fudan.edu.cn/
https://tinybeans.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
