Improper Input Validation in PACM Affects Samsung Devices
CVE-2026-20980
7HIGH
What is CVE-2026-20980?
A vulnerability in Samsung's PACM prior to the SMR Feb-2026 Release 1 allows a physical attacker to exploit improper input validation. This flaw permits the execution of arbitrary commands, potentially compromising the integrity and security of affected devices. Users are advised to update to the latest software version to mitigate this risk.
Affected Version(s)
Samsung Mobile Devices SMR Feb-2026 Release in Android 14, 15, 16