CVE-2026-21103
Analyzed Analyzed - Analysis Complete

Path Traversal in GalaxyDiagnostics Prior to SMR Sep-2026 Release 1

Vulnerability report for CVE-2026-21103, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: Samsung Mobile

Description

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 95 associated CPEs
Vendor Product Version / Range
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 15.0
samsung android 15.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 14.0
samsung android 14.0
samsung android 15.0
samsung android 15.0
samsung android 16.0
samsung android 16.0
samsung android 14.0
samsung android 15.0
samsung android 16.0
samsung android 17.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege. This means an attacker with physical access to a device could exploit this flaw to read sensitive files outside intended directories.

Detection Guidance

Detection methods for this path traversal vulnerability in GalaxyDiagnostics are not specified in the provided CVE details. Physical access is required for exploitation, so network-based detection may be limited. Check for unauthorized file access attempts or unusual system file modifications on affected devices.

Impact Analysis

An attacker could gain unauthorized access to sensitive system files, potentially exposing confidential data or compromising the device's security. This could lead to data breaches, unauthorized system modifications, or further exploitation of the device.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements under GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust due to data exposure.

Mitigation Strategies

Update GalaxyDiagnostics to the SMR Sep-2026 Release 1 or later to address the path traversal vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21103. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart