Description
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
Published: 2026-09-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an improper access control flaw in Samsung Mobile’s Collection application. The flaw exists in all versions prior to 1.0.1.14 on Android 15 and 2.0.02.7 on Android 16. A local attacker can read sensitive data exposed by the app, leading to potential information disclosure. This weakness corresponds to unauthorized access to resources and can allow leakage of private information such as user data, session tokens, or configuration settings.

Affected Systems

Affected systems are Samsung devices running the Collection service with a version older than 1.0.1.14 on Android 15 or older than 2.0.02.7 on Android 16. The issue affects the smartphone vendor’s Collection app and all Android 15 and 16 devices that have not yet applied the patch. No other vendors or OS versions are listed.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity impact, and the presence of a local attack vector limits exploitation to an attacker with physical or local device access. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting that widespread exploitation has not been observed yet. However, the lack of a remote attack vector means an attacker must already have local access, which is still a significant risk for insider or compromised device scenarios. The weakness is a classic improper access control scenario, and remediation should focus on upgrading the app and locking down local access.

Generated by OpenCVE AI on September 9, 2026 at 10:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Collection patch by installing version 1.0.1.14 or later on Android 15 devices, or version 2.0.02.7 or later on Android 16 devices.
  • If a patch is not yet available, uninstall or disable the vulnerable Collection app to prevent local data access.
  • Configure device security settings, such as enforcing biometric authentication or device encryption, so that even local attackers cannot access sensitive data through Collection.

Generated by OpenCVE AI on September 9, 2026 at 10:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung android
Samsung collection
CPEs cpe:2.3:a:samsung:collection:*:*:*:*:*:*:*:*
cpe:2.3:o:samsung:android:15.0:-:*:*:*:*:*:*
cpe:2.3:o:samsung:android:16.0:-:*:*:*:*:*:*
Vendors & Products Samsung
Samsung android
Samsung collection
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile collection
Vendors & Products Samsung Mobile
Samsung Mobile collection

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Samsung Mobile Collection Allows Local Sensitive Information Disclosure
Weaknesses CWE-284
CWE-285

Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Android Collection
Samsung Mobile Collection
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-09-10T14:16:31.662Z

Reserved: 2025-12-11T01:33:35.829Z

Link: CVE-2026-21105

cve-icon Vulnrichment

Updated: 2026-09-10T14:16:26.686Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T05:17:22.890

Modified: 2026-09-23T20:18:46.243

Link: CVE-2026-21105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:26Z

Weaknesses