Description
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Published: 2026-08-10
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung Mobile’s Weaver component contains an improper access control flaw that allows a local attacker to cause the device to become inoperable, effectively denying service. The weakness is a classic example of CWE‑284, improper access control, where unauthorized local users can exploit the vulnerability to disrupt device functionality.

Affected Systems

The vulnerability affects Samsung Mobile Devices running Weaver firmware prior to the SMR Aug‑2026 Release 1 update. All affected devices using earlier firmware versions are susceptible to this issue.

Risk and Exploitability

The CVSS score of 7 indicates high severity, while the EPSS score is not available, implying a moderate to low exploit probability under current data. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local physical or trusted access to the device to exploit this flaw, making it a local denial‑of‑service attack rather than a remote exploitation scenario.

Generated by OpenCVE AI on August 10, 2026 at 09:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Samsung Mobile firmware update (SMR Aug‑2026 Release 1) that patches the improper access control flaw in Weaver.
  • Restrict local access to the device by disabling or tightening privileges granted to user‑level processes that interact with Weaver.
  • Monitor device logs for signs of abnormal behavior or repeated attempts to exploit local resources.

Generated by OpenCVE AI on August 10, 2026 at 09:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Weaver Enables Local Attacker to Disrupt Device Functionality
Weaknesses CWE-284

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:40:40.132Z

Reserved: 2025-12-11T01:33:35.823Z

Link: CVE-2026-21064

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:00:04Z

Weaknesses