SamsungCVE-2026-21074
Samsung Bixby: insecure permissions
High7.2CVE-2026-21074 · Published Aug 10, 2026 · updated Aug 18, 2026
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-276
More Samsung advisories
All Samsung| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Samsung Smart Switch: improper input validation | Medium6.8 | No fix yet |
| Aug 10 | Samsung SmartThings: improper access control | Medium6.9 | No fix yet |
| Aug 10 | Samsung My Galaxy: improper authorization | Medium5.3 | No fix yet |
| Aug 10 | Samsung Health: improper authorization | Medium6.9 | No fix yet |
| Aug 10 | Samsung Health: improper authorization | Medium6.9 | No fix yet |
| Aug 10 | Samsung: insufficient authenticity check | Medium4.7 | No fix yet |