Improper Access Control in Galaxy Store by Samsung Products
CVE-2026-21000

7HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
16 March 2026

What is CVE-2026-21000?

A vulnerability in the Galaxy Store prior to version 4.6.03.8 allows local attackers to exploit improper access control mechanisms. This security flaw enables an unauthorized user to create files with the same privileges as the Galaxy Store, potentially leading to unauthorized actions and data exposure. Users are advised to update their Galaxy Store application to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Galaxy Store 4.6.03.8

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.