CVE-2026-21086
Analyzed Analyzed - Analysis Complete

Improper Authorization in ProxyHandler Prior to SMR Aug-2026

Vulnerability report for CVE-2026-21086, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-28

Assigner: Samsung Mobile

Description

Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 95 associated CPEs
Vendor Product Version / Range
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 16.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 17.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authorization issue in ProxyHandler before the SMR Aug-2026 Release 1. It allows local attackers to access proxy configuration settings without proper permissions.

Detection Guidance

This vulnerability involves improper authorization in ProxyHandler, allowing local attackers to access proxy configuration. Detection may require checking ProxyHandler configurations and permissions on affected systems. No specific commands are provided in the available context.

Impact Analysis

Local attackers could exploit this to view or modify proxy settings, potentially intercepting network traffic or bypassing security controls on affected systems.

Compliance Impact

The vulnerability allows local attackers to access proxy configuration due to improper authorization. This could potentially lead to unauthorized access to sensitive data, which may impact compliance with standards like GDPR or HIPAA if such data is involved.

Mitigation Strategies

Apply the SMR Aug-2026 Release 1 or later update to fix the ProxyHandler authorization issue. Ensure local attackers cannot access proxy configuration files or settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21086. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart