Description
Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
Published: 2026-07-10
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authorization in KnoxGuardManager allows a local attacker to change the application’s persistence settings without proper permissions. This is an access‑control weakness, where the authorization check is bypassed when configuring how the application stores its state. The attacker could thus alter persistence behavior, potentially enabling unauthorized data retention or change of application state.

Affected Systems

Samsung Mobile Devices running firmware that includes KnoxGuardManager before the SMR Jul‑2026 Release 1 update remain impacted. Devices that have not applied the July 2026 security patch are vulnerable.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to the device, as the attacker must manipulate the persistence configuration through the KnoxGuardManager interface. Consequently, the risk is moderate but the probability of exploitation is low, yet timely remediation is advisable to prevent future abuse.

Generated by OpenCVE AI on July 29, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung Mobile firmware to the SMR Jul‑2026 Release 1 security patch that includes the KnoxGuardManager fix.
  • If a firmware update cannot be applied immediately, block KnoxGuardManager from altering persistence settings by disabling the feature through device policy or reducing the application’s privileges.
  • Monitor device logs for unauthorized changes to application persistence configuration and notify administrators when such events occur.
  • Adopt general mobile security best practices, such as enforcing the principle of least privilege for installed applications.

Generated by OpenCVE AI on July 29, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung KnoxGuardManager Persistence Configuration
Weaknesses CWE-284

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung KnoxGuardManager Persistence Configuration
Weaknesses CWE-284

Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in KnoxGuardManager Allows Persistence Configuration Modification
Weaknesses CWE-284

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in KnoxGuardManager Allows Persistence Configuration Modification
Weaknesses CWE-284

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization in KnoxGuardManager Allows Local Persistence Configuration Bypass
Weaknesses CWE-284

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization in KnoxGuardManager Allows Local Persistence Configuration Bypass
Weaknesses CWE-284

Sun, 12 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in KnoxGuardManager Enables Persistence Configuration Tampering
Weaknesses CWE-284

Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in KnoxGuardManager Enables Persistence Configuration Tampering
Weaknesses CWE-284

Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T14:33:24.915Z

Reserved: 2025-12-11T01:33:35.816Z

Link: CVE-2026-21044

cve-icon Vulnrichment

Updated: 2026-07-10T14:33:17.992Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses

No weakness.