Description
Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
Published: 2026-07-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control flaw (CWE‑284) in SamsungSEAgentService allows a local attacker to retrieve sensitive information, resulting in information disclosure (CWE‑200). The vulnerability is limited to local execution on the device and does not require remote code execution or network connectivity. If successfully exploited, an attacker who can physically access the device or has privileged local access could read confidential data managed by the SE Agent service, compromising user privacy and device integrity.

Affected Systems

Samsung Mobile Devices that run SamsungSEAgentService versions prior to the SMR Jul-2026 Release 1 update. No specific patch version numbers are listed, and the vendor has not supplied further version details in this advisory.

Risk and Exploitability

The moderate CVSS score of 6.9 indicates a significant security impact, but the EPSS score of < 1 % suggests a very low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV. The flaw requires physical or local administrative access, so an attacker would need to own or have a privileged user on the device to leverage it. Because the flaw exposes sensitive information, it remains a significant risk for devices that have not yet been updated to the July 2026 release.

Generated by OpenCVE AI on July 28, 2026 at 08:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the July 2026 Samsung Mobile security update that includes the fix for SamsungSEAgentService.
  • Disable or uninstall any applications that provide access to SamsungSEAgentService via device settings or ADB to reduce the local attack surface.
  • Ensure that only trusted applications are granted permissions that allow them to interact with SamsungSEAgentService, removing any unnecessary apps that have local access rights.

Generated by OpenCVE AI on July 28, 2026 at 08:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control Exposes Sensitive Information in SamsungSEAgentService
Weaknesses CWE-200
CWE-284

Sat, 25 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control Exposes Sensitive Information in SamsungSEAgentService
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control in SamsungSEAgentService Leading to Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control in SamsungSEAgentService Leading to Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Enabling Local Information Disclosure
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Enabling Local Information Disclosure
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Allows Local Information Disclosure
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in SamsungSEAgentService Allows Local Information Disclosure
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SamsungSEAgentService Enables Sensitive Info Exposure
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SamsungSEAgentService Enables Sensitive Info Exposure
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T14:31:30.930Z

Reserved: 2025-12-11T01:33:35.815Z

Link: CVE-2026-21041

cve-icon Vulnrichment

Updated: 2026-07-10T14:31:25.993Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses

No weakness.