Impact
Improper access control in Samsung’s ManagedProvisioning component allows a local attacker to install arbitrary applications on a device. The flaw permits the attacker to bypass normal application install controls, potentially leading to execution of malicious code and exposure of sensitive data or device functions. The vulnerability is classified as an improper access control weakness.
Affected Systems
Samsung Mobile Devices that are running ManagedProvisioning prior to the SMR Sep‑2026 Release 1 are affected. No specific build numbers are listed beyond the release identifier, but any device relying on the legacy provisioning system is at risk.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability carries moderate impact severity. The EPSS score is not listed, and the vulnerability is not included in the CISA KEV catalog, implying limited or unknown active exploitation. The likely attack vector is local; an attacker must have local or physical access to the device to exploit the flaw, for example by logging in or using a local privileged account. Successful exploitation would enable the attacker to install benign‑looking applications that could run arbitrary code or exfiltrate device data.
OpenCVE Enrichment