CVE-2026-20976: Input Validation
Published Jan 9, 2026
·Updated
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
Affected Software
2 affected components
Samsung Galaxy Store<4.6.02
Samsung Galaxy Store<4.6.02.0
Event History
Jan 9, 2026
CVE Published
via MITRE·06:17 AM
Data Sourced
via MITRE·06:17 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityAffected Software
Oct 20, 58013
Event
via FIRST·12:59 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-20976?
CVE-2026-20976 is classified as a high severity vulnerability due to its ability to allow local attackers to execute arbitrary scripts.
2
How do I fix CVE-2026-20976?
To fix CVE-2026-20976, update the Samsung Galaxy Store to version 4.6.02 or later.
3
What impact does CVE-2026-20976 have on users?
CVE-2026-20976 can allow an attacker to run unauthorized scripts, potentially compromising user data and device security.
4
Who is affected by CVE-2026-20976?
Users of Samsung Galaxy Store versions prior to 4.6.02 are affected by CVE-2026-20976.
5
Is CVE-2026-20976 being actively exploited?
There is currently no public information indicating active exploitation of CVE-2026-20976.