URL Redirection Vulnerability in Samsung Account Affects Samsung Devices
CVE-2026-20994

6.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
16 March 2026

What is CVE-2026-20994?

A URL redirection vulnerability in Samsung Account prior to version 15.5.01.1 enables remote attackers to potentially obtain access tokens, leading to unauthorized access. This could allow malicious users to exploit sensitive user information, emphasizing the importance of updating to the latest security patches.

Affected Version(s)

Samsung Account 15.5.01.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.