Path Traversal Vulnerability in Galaxy Store by Samsung
CVE-2026-21001

5.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
16 March 2026

What is CVE-2026-21001?

A path traversal vulnerability exists in Samsung's Galaxy Store prior to version 4.6.03.8, which allows local attackers to manipulate file path structures. By exploiting this vulnerability, attackers can potentially create files with the privileges of the Galaxy Store. This could lead to unauthorized access to sensitive information or system manipulation if not addressed promptly. Users are advised to upgrade to the latest version of the Galaxy Store to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Galaxy Store 4.6.03.8

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.