Description
Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control flaw in SamsungSEAgentService allows a local attacker to retrieve sensitive information, resulting in an information disclosure vulnerability. The flaw permits reading data that the SE Agent service protects, potentially exposing personal or device‑specific data. The impact is confined to confidentiality; there is no mention of integrity or availability compromise.

Affected Systems

Samsung Mobile Devices that have not applied the Samsung Mobile security update released in July 2026, which contains an updated SE Agent Service. No specific patch or version numbers are listed beyond the update month, so any device running the pre‑July 2026 release of SamsungSEAgentService is vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate level of severity, while the EPSS score of < 1 % signals a very low probability of exploitation currently. The vulnerability requires local access and does not involve remote code execution or network exploitation; therefore physical or privileged local access is needed. Because the flaw leads to sensitive data exposure and is not listed in CISA KEV, affected devices should update promptly, though the risk of widespread exploitation remains low at present.

Generated by OpenCVE AI on August 5, 2026 at 03:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the July 2026 Samsung Mobile security update that includes the SamsungSEAgentService fix.
  • If the update cannot be applied immediately, disable or uninstall applications or services that expose SamsungSEAgentService interfaces, such as ADB or device‑settings utilities, to limit local attack surface.
  • Remove or restrict permissions for applications that may interact with SamsungSEAgentService, ensuring only trusted apps have local access rights.

Generated by OpenCVE AI on August 5, 2026 at 03:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Allows Local Sensitive Information Disclosure
Weaknesses CWE-284

Tue, 04 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Vulnerability in SamsungSEAgentService Allows Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Sat, 01 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Vulnerability in SamsungSEAgentService Allows Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control Exposes Sensitive Information in SamsungSEAgentService
Weaknesses CWE-200
CWE-284

Sat, 25 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control Exposes Sensitive Information in SamsungSEAgentService
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control in SamsungSEAgentService Leading to Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control in SamsungSEAgentService Leading to Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Enabling Local Information Disclosure
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Enabling Local Information Disclosure
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Allows Local Information Disclosure
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Allows Local Information Disclosure
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SamsungSEAgentService Enables Sensitive Info Exposure
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SamsungSEAgentService Enables Sensitive Info Exposure
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T14:31:30.930Z

Reserved: 2025-12-11T01:33:35.815Z

Link: CVE-2026-21041

cve-icon Vulnrichment

Updated: 2026-07-10T14:31:25.993Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T05:16:34.663

Modified: 2026-07-10T17:56:00.910

Link: CVE-2026-21041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T03:15:05Z

Weaknesses