CVE-2026-21106
CVE-2026-21106 is a medium-severity vulnerability with a CVSS 4.0 base score of 5.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-925.
Key facts
- Severity: Medium (CVSS 4.0 base score 5.1)
- EPSS exploit prediction: 0% (1st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-925
- Published:
- Last modified:
Description
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Frequently asked questions
- What is CVE-2026-21106?
- Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
- How severe is CVE-2026-21106?
- CVE-2026-21106 has a CVSS 4.0 base score of 5.1, rated medium severity.
- Is CVE-2026-21106 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (1st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-21106?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-21106 published?
- CVE-2026-21106 was published on 2026-09-09 and last updated on 2026-09-10.
References
Other CWE-925 vulnerabilities
- CVE-2024-10576 — Critical (CVSS 9.4): Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast…
- CVE-2026-33173 — Medium (CVSS 5.3): Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1,…
- CVE-2023-44126 — Low (CVSS 3.6): The vulnerability is that the Call management ("com.android.server.telecom") app patched by LG sends a lot of LG-owned…