Description
Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
Published: 2026-07-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw in the SmartThingsKit component that allows a local attacker to read sensitive data stored on Samsung Mobile devices. The weakness is characterized by CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control). Because the component bypasses normal authorization checks, a victim can retrieve user identifiers, configuration settings, or other confidential data from the device’s local storage.

Affected Systems

Samsung Mobile devices that run SmartThingsKit firmware released before the SMR Jul‑2026 Release 1 are affected. The vendor has not identified specific device models, so the scope potentially includes all devices running this unpatched firmware.

Risk and Exploitability

The CVSS v3.1 score of 5.1 classifies the issue as moderate severity, and the EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires local access, which could be physical possession of the device or control over the local network. Consequently, an adversary would need to be present near the device or compromise a network channel that communicates with it to invoke the flaw.

Generated by OpenCVE AI on August 4, 2026 at 07:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Samsung Mobile firmware update that includes the SmartThingsKit fix (SMR Jul‑2026 Release 1 or later).
  • If a firmware update cannot be applied immediately, isolate the device from untrusted networks, disable remote management features, and restrict physical access to reduce the risk of local exploitation.
  • If SmartThingsKit is not required for the device’s normal operation, uninstall or permanently disable the application to eliminate the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 07:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Local Improper Access Control in Samsung SmartThingsKit Enables Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Sat, 01 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SmartThingsKit Allows Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SmartThingsKit Allows Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass Exposing Sensitive Information in SmartThingsKit
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass Exposing Sensitive Information in SmartThingsKit
Weaknesses CWE-200
CWE-284

Fri, 17 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Information via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Wed, 15 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Information via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Data via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Data via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Sensitive Information Disclosure via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Sensitive Information Disclosure via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T13:15:56.114Z

Reserved: 2025-12-11T01:33:35.817Z

Link: CVE-2026-21050

cve-icon Vulnrichment

Updated: 2026-07-10T13:15:52.053Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T05:16:35.650

Modified: 2026-07-10T17:56:00.910

Link: CVE-2026-21050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control