CVE-2026-21019: Input Validation
Published May 13, 2026
·Updated
Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.
Affected Software
1 affected component
Samsung Galaxy Watch<SMR May-2026 Release 1
Event History
May 13, 2026
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-21019?
CVE-2026-21019 is considered a high severity vulnerability due to its potential for arbitrary code execution with system privileges.
2
How do I fix CVE-2026-21019?
To fix CVE-2026-21019, update your Samsung Galaxy Watch to the SMR May-2026 Release 1 or a later version.
3
Who is affected by CVE-2026-21019?
CVE-2026-21019 affects Samsung Galaxy Watches running versions prior to SMR May-2026 Release 1.
4
What kind of attack can CVE-2026-21019 facilitate?
CVE-2026-21019 allows a local attacker to execute arbitrary code with system privileges on the affected device.
5
What component is vulnerable in CVE-2026-21019?
The vulnerability in CVE-2026-21019 lies in the improper input validation in the FacAtFunction component of the affected watches.