Path Traversal Vulnerability in Galaxy Store by Samsung
CVE-2026-21001

5.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
16 March 2026

What is CVE-2026-21001?

A path traversal vulnerability exists in Samsung's Galaxy Store prior to version 4.6.03.8, which allows local attackers to manipulate file path structures. By exploiting this vulnerability, attackers can potentially create files with the privileges of the Galaxy Store. This could lead to unauthorized access to sensitive information or system manipulation if not addressed promptly. Users are advised to upgrade to the latest version of the Galaxy Store to mitigate risks associated with this vulnerability.

Affected Version(s)

Galaxy Store 4.6.03.8

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.