CVE-2026-20994: Medium severity Samsung Samsung Account vulnerability
Published Mar 16, 2026
·Updated
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
Affected Software
2 affected components
Samsung Samsung Account<15.5.01.1
Samsung Account<15.5.01.1
Event History
Mar 16, 2026
CVE Published
via MITRE·04:32 AM
Data Sourced
via MITRE·04:32 AM
DescriptionWeakness
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-20994?
CVE-2026-20994 is considered a moderate severity vulnerability due to its potential to expose access tokens.
2
What is CVE-2026-20994's impact on Samsung Account?
CVE-2026-20994 allows remote attackers to leverage URL redirection vulnerabilities, potentially gaining unauthorized access to user access tokens.
3
How do I fix CVE-2026-20994?
To mitigate CVE-2026-20994, update Samsung Account to version 15.5.01.1 or later.
4
Which versions of Samsung Account are affected by CVE-2026-20994?
CVE-2026-20994 affects Samsung Account versions prior to 15.5.01.1.
5
Is it necessary to update to fix CVE-2026-20994?
Yes, updating to a version later than 15.5.01.1 is essential to resolve the vulnerability in CVE-2026-20994.