CVE-2026-21075
CVE-2026-21075 is a medium-severity vulnerability with a CVSS 4.0 base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-939.
Key facts
- Severity: Medium (CVSS 4.0 base score 5.3)
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-939
- Published:
- Last modified:
Description
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
Frequently asked questions
- What is CVE-2026-21075?
- Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
- How severe is CVE-2026-21075?
- CVE-2026-21075 has a CVSS 4.0 base score of 5.3, rated medium severity.
- Is CVE-2026-21075 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-21075?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-21075 published?
- CVE-2026-21075 was published on 2026-08-10 and last updated on 2026-08-18.
References
Other CWE-939 vulnerabilities
- CVE-2024-33606 — High (CVSS 8.8): An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing…
- CVE-2026-6445 — High (CVSS 8.7): A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive…
- CVE-2026-35394 — High (CVSS 8.3): Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open_url tool in…
- CVE-2026-53408 — High (CVSS 8.1): Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before…
- CVE-2026-53407 — High (CVSS 8.1): Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before…
- CVE-2026-33335 — High (CVSS 8.0): Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0,…