CVE-2026-21097
Analyzed Analyzed - Analysis Complete

Improper Authentication in ActivityTaskManagerService

Vulnerability report for CVE-2026-21097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: Samsung Mobile

Description

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 95 associated CPEs
Vendor Product Version / Range
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 16.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 17.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authentication issue in ActivityTaskManagerService found in Samsung devices before the September 2026 Release 1 update. It allows local attackers with high privileges to launch arbitrary activities on the device.

Detection Guidance

This vulnerability involves improper authentication in ActivityTaskManagerService, which may allow local privileged attackers to launch arbitrary activities. Detection would require checking for unauthorized activity launches or unusual system behavior. No specific commands are provided in the available context.

Impact Analysis

A local privileged attacker could exploit this to execute unauthorized activities on your device, potentially leading to unauthorized access, data manipulation, or other malicious actions depending on the activity launched.

Compliance Impact

The vulnerability allows local privileged attackers to bypass authentication, which could lead to unauthorized access to sensitive data or system functions. This may violate compliance requirements for data protection and access control in standards like GDPR and HIPAA, depending on the affected system's use case.

Mitigation Strategies

Apply the SMR Sep-2026 Release 1 update or later to patch ActivityTaskManagerService. Ensure all Samsung devices are updated to the latest security firmware.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart