Improper Access Control in Weaver Affects Samsung Devices
CVE-2026-21064

7HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
10 August 2026

What is CVE-2026-21064?

An improper access control vulnerability exists in Weaver prior to Release 1 of the SMR Aug-2026. This flaw enables local attackers to manipulate device settings and potentially render the device inoperable. Users are urged to upgrade to the latest release to mitigate risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Aug-2026 Release in Android 14, 15, 16

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.