Improper Access Control in Samsung SystemUI Exposes Vulnerability to Local Attackers
CVE-2026-21100

6.9MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21100?

Samsung's SystemUI has a vulnerability due to improper access control, which permits local attackers to initiate arbitrary activities on devices running versions prior to SMR Sep-2026 Release 1. This flaw can potentially lead to unauthorized access and compromise the device's security. Users are encouraged to update their systems to the latest security release to mitigate the risks associated with this vulnerability.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.