Path Traversal Vulnerability in GalaxyDiagnostics Affects Samsung Devices
CVE-2026-21103

6.8MEDIUM

Key Information:

Vendor

Samsung

Vendor
CVE Published:
9 September 2026

What is CVE-2026-21103?

A path traversal vulnerability in GalaxyDiagnostics allows physical attackers to exploit the system and gain unauthorized access to sensitive files by manipulating file paths. This flaw affects users of GalaxyDiagnostics prior to the September 2026 SMR Release 1 and highlights the importance of ensuring systems are up-to-date to prevent potential breaches.

Affected Version(s)

Samsung Mobile Devices SMR Sep-2026 Release in Android 14, 15, 16, 17

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.