Description
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Local Code Installation via Improper Access Control
Action: Apply Update
AI Analysis

Impact

Improper access control in Samsung’s ManagedProvisioning component allows a local attacker to install arbitrary applications on a device. The flaw permits the attacker to bypass normal application install controls, potentially leading to execution of malicious code and exposure of sensitive data or device functions. The vulnerability is classified as an improper access control weakness.

Affected Systems

Samsung Mobile Devices that are running ManagedProvisioning prior to the SMR Sep‑2026 Release 1 are affected. No specific build numbers are listed beyond the release identifier, but any device relying on the legacy provisioning system is at risk.

Risk and Exploitability

With a CVSS score of 6.9 the vulnerability carries moderate impact severity. The EPSS score is not listed, and the vulnerability is not included in the CISA KEV catalog, implying limited or unknown active exploitation. The likely attack vector is local; an attacker must have local or physical access to the device to exploit the flaw, for example by logging in or using a local privileged account. Successful exploitation would enable the attacker to install benign‑looking applications that could run arbitrary code or exfiltrate device data.

Generated by OpenCVE AI on October 2, 2026 at 02:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the SMR Sep‑2026 Release 1 software update on all Samsung Mobile Devices to address the access‑control flaw.
  • If the device cannot receive the update, disable ManagedProvisioning or remove the feature from the device configuration so local installation of applications is no longer possible.
  • Enforce a policy that limits local account privileges and requires application code signing verification before installation, ensuring only trusted applications are allowed.

Generated by OpenCVE AI on October 2, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Failure Enabling Arbitrary Application Installation via ManagedProvisioning
First Time appeared Samsung Mobile
Samsung Mobile samsung Mobile Devices
Weaknesses CWE-284
Vendors & Products Samsung Mobile
Samsung Mobile samsung Mobile Devices

Fri, 02 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
Description Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Mobile Devices
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-10-02T01:05:39.572Z

Reserved: 2025-12-11T01:33:35.834Z

Link: CVE-2026-21140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T02:17:02.157

Modified: 2026-10-02T02:17:02.157

Link: CVE-2026-21140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T02:30:18Z

Weaknesses