Description
Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox.
Published: 2026-07-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Samsung Email versions older than 6.2.13.1 allows an attacker to specify file names or paths that the application will accept for file creation. The flaw enables the creation of arbitrary files entirely within the Email app sandbox, potentially allowing modification of existing files or insertion of new ones. This can compromise the confidentiality, integrity, or availability of the app’s internal state by altering configuration files, inserting malicious payloads, or corrupting data stored by the application.

Affected Systems

Samsung Mobile devices running Samsung Email versions earlier than 6.2.13.1 are affected. The vulnerability resides solely in the application code, not the underlying operating system or device hardware.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity issue, and the EPSS score of less than 1% shows a low likelihood of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to the device; the most likely scenario is that an attacker who has physical possession of or otherwise locally compromised the device can trigger the flaw.

Generated by OpenCVE AI on July 29, 2026 at 11:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Email to version 6.2.13.1 or newer to eliminate the input‑validation weakness.
  • If an immediate upgrade is not possible, configure the device’s application policy to restrict file creation to a whitelisted set of directories within the Email sandbox, thereby limiting the attack surface.
  • Apply device‑management controls that prevent untrusted applications from interacting with Samsung Email in ways that could trigger the flaw.

Generated by OpenCVE AI on July 29, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local File Creation Vulnerability in Samsung Email
Weaknesses CWE-20
CWE-22

Wed, 22 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Local File Creation Vulnerability in Samsung Email

Fri, 17 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Allowing Arbitrary File Creation in Samsung Email
Weaknesses CWE-20
CWE-22

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Allowing Arbitrary File Creation in Samsung Email
Weaknesses CWE-20
CWE-22

Mon, 13 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Samsung Email Allows Local File Creation
Weaknesses CWE-20
CWE-22

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Samsung Email Allows Local File Creation
Weaknesses CWE-20
CWE-22

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local File Creation via Improper Input Validation in Samsung Email
Weaknesses CWE-20
CWE-22

Fri, 10 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local File Creation via Improper Input Validation in Samsung Email

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Email
Vendors & Products Samsung Mobile
Samsung Mobile samsung Email

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox.
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Email
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T11:41:13.002Z

Reserved: 2025-12-11T01:33:35.820Z

Link: CVE-2026-21053

cve-icon Vulnrichment

Updated: 2026-07-10T11:41:02.978Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:30:17Z

Weaknesses

No weakness.