Improper Input Validation in wpa_supplicant Affects Samsung Devices
CVE-2026-21094

6.1MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21094?

The wpa_supplicant component in Samsung devices is affected by a vulnerability that arises from improper input validation. This flaw allows adjacent attackers to manipulate the system by writing out-of-bounds memory, potentially leading to unintended behavior or security breaches. Prompt updates to the latest release are recommended to mitigate any risk this vulnerability may pose.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.