Description
Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.
Published: 2026-07-10
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw exists in the Wallpaper service of Samsung Mobile Devices. It allows a local attacker with privileged access to read arbitrary files on the device with system server privileges, exposing sensitive data and enabling further abuse. The weakness corresponds to CWE-22 (Path Traversal) and CWE-285 (Privilege Management).

Affected Systems

Samsung Mobile Devices running firmware versions prior to SMR Jul-2026 Release 1 are affected. No specific sub-product or version list was provided.

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity. The attacker must be local and already hold privileged access; however, the flaw permits escalation to system server privilege, a critical capability. The EPSS score of < 1% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation.

Generated by OpenCVE AI on July 28, 2026 at 08:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to SMR Jul-2026 Release 1 or newer via the Samsung firmware update mechanism to patch the Path Traversal flaw (CWE-22).
  • Configure or disable the Wallpaper service so that it cannot resolve arbitrary file paths, limiting access to only approved directories; this mitigates the CWE-22 vulnerability by enforcing strict input validation.
  • Apply least‑privilege principles to the Wallpaper service—ensure it runs with minimal permissions and does not possess system server rights—to mitigate the privilege escalation risk (CWE-285).

Generated by OpenCVE AI on July 28, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Path Traversal in Wallpaper Service Enables System Server File Access
Weaknesses CWE-22
CWE-285

Wed, 22 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Wallpaper Service Enables System Server File Access
Weaknesses CWE-22
CWE-285

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Path Traversal in Wallpaper Service
Weaknesses CWE-22
CWE-285

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Path Traversal in Wallpaper Service
Weaknesses CWE-22
CWE-285

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Wallpaper Service Path Traversal Enabling System Server File Access
Weaknesses CWE-22
CWE-269

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Wallpaper Service Path Traversal Enabling System Server File Access
Weaknesses CWE-22
CWE-269

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Wallpaper Service Path Traversal
Weaknesses CWE-22
CWE-264

Fri, 10 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Wallpaper Service Path Traversal
Weaknesses CWE-22
CWE-264

Fri, 10 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.
References
Metrics cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-11T03:55:20.258Z

Reserved: 2025-12-11T01:33:35.816Z

Link: CVE-2026-21043

cve-icon Vulnrichment

Updated: 2026-07-10T12:24:00.729Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses

No weakness.