CVE-2026-21000: Path Traversal
Published Mar 16, 2026
·Updated
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
Affected Software
2 affected components
Samsung Galaxy Store<4.6.03.8
Samsung Galaxy Store<4.6.03.8
Event History
Mar 16, 2026
CVE Published
via MITRE·04:32 AM
Data Sourced
via MITRE·04:32 AM
DescriptionWeakness
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21000?
CVE-2026-21000 is rated as a medium severity vulnerability due to improper access control in Galaxy Store.
2
How do I fix CVE-2026-21000?
To mitigate CVE-2026-21000, update Galaxy Store to version 4.6.03.8 or later.
3
What kind of attack can CVE-2026-21000 enable?
CVE-2026-21000 allows a local attacker to create files with Galaxy Store privileges.
4
Which versions of Galaxy Store are affected by CVE-2026-21000?
Galaxy Store versions prior to 4.6.03.8 are affected by CVE-2026-21000.
5
Who is the vendor associated with CVE-2026-21000?
The vendor associated with CVE-2026-21000 is Samsung.