CVE-2026-21105
Analyzed Analyzed - Analysis Complete

Improper Access Control in Collection for Android

Vulnerability report for CVE-2026-21105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-23

Assigner: Samsung Mobile

Description

Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-23
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
samsung collection to 1.0.1.14 (exc)
samsung collection to 2.0.02.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Improper access control in the Collection software allows local attackers to access sensitive information. This flaw exists in versions prior to 1.0.1.14 for Android 15 and 2.0.02.7 for Android 16.

Detection Guidance

The provided CVE details do not include specific detection methods or commands. Detection would require checking the installed version of Samsung Collection against the vulnerable versions (1.0.1.14 for Android 15 or 2.0.02.7 for Android 16) and verifying if improper access controls exist.

Impact Analysis

Local attackers could exploit this to access sensitive data stored or processed by the Collection software on affected Android devices. This may lead to unauthorized data exposure or privacy breaches.

Compliance Impact

The vulnerability involves improper access control allowing local attackers to access sensitive information. This could lead to unauthorized data exposure, potentially violating GDPR's data protection requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Update the Samsung Collection app to version 1.0.1.14 for Android 15 or 2.0.02.7 for Android 16 to address the improper access control issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart