Description
Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
Published: 2026-07-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows a local attacker to read data considered confidential. The vulnerability is present in all builds released before SMR Jul‑2026 Release 1 on Samsung Mobile devices. Because the component can bypass normal authorization checks, an attacker can gain access to information such as user identifiers, configuration data, or credentials. Based on the description, it is inferred that the weakness corresponds to CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).

Affected Systems

Devices that run a SmartThingsKit firmware prior to SMR Jul-2026 Release 1 on Samsung Mobile devices are affected. The vendor does not specify which device models are included, so it is unclear whether the vulnerability spans all scope of the impact across device models is not provided in the available information.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, meaning exploitation is unlikely in the wild. The flaw requires local access, such as physical presence or control over the local network, for an attacker to exploit the vulnerability.

Generated by OpenCVE AI on July 28, 2026 at 08:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the SMR Jul‑2026 Release 1 or a later version that contains the SmartThingsKit fix.
  • If a firmware update cannot be applied immediately, isolate the device from untrusted networks, disable remote management features, and restrict local physical access to minimize the risk of an attacker exploiting the flaw.
  • If SmartThingsKit is not required for the device’s operation, permanently remove or disable the application or service to eliminate the attack surface.

Generated by OpenCVE AI on July 28, 2026 at 08:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in SmartThingsKit Allows Sensitive Information Disclosure
Weaknesses CWE-200
CWE-284

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass Exposing Sensitive Information in SmartThingsKit
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass Exposing Sensitive Information in SmartThingsKit
Weaknesses CWE-200
CWE-284

Fri, 17 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Information via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Wed, 15 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Information via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Data via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Mon, 13 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Local Access to Sensitive Data via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Sensitive Information Disclosure via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Sensitive Information Disclosure via Improper Access Control in SmartThingsKit
Weaknesses CWE-200
CWE-284

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T13:15:56.114Z

Reserved: 2025-12-11T01:33:35.817Z

Link: CVE-2026-21050

cve-icon Vulnrichment

Updated: 2026-07-10T13:15:52.053Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control