Path Traversal Vulnerability in ImsService by Samsung
CVE-2026-21092

8.8HIGH

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21092?

A path traversal vulnerability exists in ImsService, which enables remote attackers to manipulate file paths. This can allow unauthorized creation of image files with elevated system server privileges, potentially compromising the integrity of the system. Users are advised to update to the SMR Sep-2026 Release 1 to mitigate this risk.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.