Description
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
Published: 2026-07-10
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path‑traversal flaw exists in Samsung Mobile’s SemClipboardService that allows a locally privileged user to craft requests resolving to arbitrary file paths. This vulnerability can enable the attacker to read or modify files protected by system privileges, thereby compromising confidentiality and integrity of critical device data. While it does not provide direct remote code execution, the ability to access sensitive files could be leveraged to facilitate further privilege escalation or data exfiltration if other weaknesses are present.

Affected Systems

Samsung Mobile Devices running firmware versions prior to SMR Jul‑2026 Release 1, which include the unpatched SemClipboardService, are affected.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, and the EPSS score of <1 % combined with its absence from CISA’s KEV catalog suggests that exploitation activity is limited. The attack vector is local; an attacker must have user‑level access to trigger the path‑traversal. Because the flaw does not allow remote exploitation and requires local privileged execution, the overall risk for immediate compromise remains low, though attentive monitoring is advised.

Generated by OpenCVE AI on August 3, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to firmware SMR Jul‑2026 Release 1 to patch the SemClipboardService path‑traversal flaw (CWE‑22).
  • Disable or restrict SemClipboardService if it is not required for device operation.
  • Limit local user privileges so that only trusted accounts can access the clipboard service.
  • Monitor device logs for abnormal file access involving the clipboard service.

Generated by OpenCVE AI on August 3, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Fri, 31 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title SemClipboardService Path Traversal Allowing Access to System Files
Weaknesses CWE-22

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title SemClipboardService Path Traversal Allowing Access to System Files
Weaknesses CWE-22

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in SemClipboardService Enables Local Privilege Escalation
Weaknesses CWE-22

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in SemClipboardService Enables Local Privilege Escalation
Weaknesses CWE-22

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Path Traversal in Samsung SemClipboardService
Weaknesses CWE-22

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Path Traversal in Samsung SemClipboardService
Weaknesses CWE-22

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in SemClipboardService Allows Local Privilege Escalation
Weaknesses CWE-22

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in SemClipboardService Allows Local Privilege Escalation
Weaknesses CWE-22

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Path traversal in SemClipboardService allows local privileged attackers to access system‑privileged files
Weaknesses CWE-22

Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Path traversal in SemClipboardService allows local privileged attackers to access system‑privileged files
Weaknesses CWE-22

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-14T14:31:24.887Z

Reserved: 2025-12-11T01:33:35.820Z

Link: CVE-2026-21052

cve-icon Vulnrichment

Updated: 2026-07-10T11:41:45.108Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T05:16:35.877

Modified: 2026-07-14T15:17:01.420

Link: CVE-2026-21052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')