Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
SamsungCVE-2026-21140

Samsung ManagedProvisioning: improper access control

Medium6.9CVE-2026-21140 · Published Oct 2, 2026

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

Samsung advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)

More Samsung advisories

All Samsung
Advisory
Samsung Escargot: integer overflow
Medium5.5Sep 15
Samsung rLottie: stack buffer overflow
Medium4.4Sep 15
Samsung Cloud Assistant: local attacker could disable enhanced data protection
Medium5.1Sep 9
Samsung Notes: out-of-bounds write
Medium6.9Sep 9
Samsung Bixby Touch: information disclosure
Medium6.9Sep 9
Samsung Watch Plugin: improper access control
Low2.1Sep 9