Description
Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper access control weakness in the Settings application of Samsung Mobile devices prior to the SMR Jul-2026 Release 1 firmware. A local attacker who can access the device can use the Settings interface to change Theft protection options, potentially disabling or modifying the device’s predefined security policies. By doing so, the attacker can remove safeguards designed to deter theft or assist recovery, thereby undermining the device’s overall security posture. The underlying weakness aligns with CWE-284, Improper Access Control.

Affected Systems

Samsung Mobile Devices running firmware versions before the SMR Jul-2026 Release 1 are affected. The issue is present in all devices that have not yet been updated to that release or later.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium‑to‑high severity vulnerability. The EPSS score of <1% shows a low likelihood of exploitation, and the flaw is not listed in CISA’s KEV catalog. Because the vulnerability requires local access to the device, the attack vector is limited to physical or local software access. Exploitation would allow an attacker to subvert theft protection settings, enabling unauthorized use of the device.

Generated by OpenCVE AI on July 29, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the SMR Jul-2026 Release 1 firmware update or any later release on all affected Samsung Mobile devices
  • Restrict local user privileges so that only authorized administrators can modify system settings, enforcing role‑based access control
  • Implement monitoring of device logs to detect changes to Theft protection settings and review anomalies periodically

Generated by OpenCVE AI on July 29, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile Settings Enables Local Attacker to Disable Theft Protection
Weaknesses CWE-284

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Access Allows Theft Protection Configuration via Improper Access Control
Weaknesses CWE-284

Thu, 23 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Local Access Allows Theft Protection Configuration via Improper Access Control
Weaknesses CWE-284

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile Settings Enables Theft Protection Modification
Weaknesses CWE-284

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile Settings Enables Theft Protection Modification
Weaknesses CWE-284

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Local Attackers to Alter Theft Protection Settings on Samsung Mobile Devices
Weaknesses CWE-284

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allows Local Attackers to Alter Theft Protection Settings on Samsung Mobile Devices
Weaknesses CWE-284

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile Settings Enables Theft Protection Configuration
Weaknesses CWE-284

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile Settings Enables Theft Protection Configuration
Weaknesses CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Attackers Can Alter Theft Protection Settings via Improper Access Control
Weaknesses CWE-284

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Attackers Can Alter Theft Protection Settings via Improper Access Control
Weaknesses CWE-284

Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung mobile Devices
Vendors & Products Samsung
Samsung mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T15:17:27.349Z

Reserved: 2025-12-11T01:33:35.808Z

Link: CVE-2026-21039

cve-icon Vulnrichment

Updated: 2026-07-10T15:17:24.603Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses