CVE-2026-20985
Unknown
Unknown - Not Provided
Improper Input Validation in Samsung Members Enables Privileged Activity
Publication date: 2026-02-04
Last updated on: 2026-02-25
Assigner: Samsung Mobile
Description
Description
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | members | to 5.6.00.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |