Description
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
Published: 2026-07-10
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw exists in the SemClipboardService component of Samsung Mobile firmware, allowing a local user to craft requests that resolve to arbitrary file paths. By exploiting this weakness, an attacker can read or modify files normally protected with system privileges, compromising data confidentiality and integrity. The vulnerability does not grant remote code execution directly but can be leveraged to elevate privileges further if additional weaknesses exist.

Affected Systems

Samsung Mobile Devices running firmware versions prior to SMR Jul‑2026 Release 1, which include the unpatched SemClipboardService, are affected.

Risk and Exploitability

The CVSS score of 6.8 denotes moderate severity, and the EPSS score of < 1 % together with the lack of listing in CISA’s KEV catalog indicate that exploitation is not currently widespread. The attack vector is local; an adversary must have user‑level access to trigger the path traversal. The narrow exploitation window and absence of network reachability reduce the overall risk of immediate compromise.

Generated by OpenCVE AI on July 25, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to firmware SMR Jul‑2026 Release 1 to patch the SemClipboardService path‑traversal flaw (CWE-22).
  • Disable or restrict SemClipboardService if it is not required for device operation.
  • Monitor clipboard activity and system file access for anomalous behavior.

Generated by OpenCVE AI on July 25, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title SemClipboardService Path Traversal Allowing Access to System Files
Weaknesses CWE-22

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in SemClipboardService Enables Local Privilege Escalation
Weaknesses CWE-22

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in SemClipboardService Enables Local Privilege Escalation
Weaknesses CWE-22

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Path Traversal in Samsung SemClipboardService
Weaknesses CWE-22

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Path Traversal in Samsung SemClipboardService
Weaknesses CWE-22

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in SemClipboardService Allows Local Privilege Escalation
Weaknesses CWE-22

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in SemClipboardService Allows Local Privilege Escalation
Weaknesses CWE-22

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Path traversal in SemClipboardService allows local privileged attackers to access system‑privileged files
Weaknesses CWE-22

Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Path traversal in SemClipboardService allows local privileged attackers to access system‑privileged files
Weaknesses CWE-22

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-14T14:31:24.887Z

Reserved: 2025-12-11T01:33:35.820Z

Link: CVE-2026-21052

cve-icon Vulnrichment

Updated: 2026-07-10T11:41:45.108Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T20:15:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')