CVE-2026-21021: Input Validation
Published May 13, 2026
·Updated
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
Affected Software
11 affected components
Samsung Routines<SMR May-2026 Release 1
Samsung Android=16.0
Samsung Android=16.0-smr-apr-2026-r1
Samsung Android=16.0-smr-aug-2025-r1
Samsung Android=16.0-smr-dec-2025-r1
Samsung Android=16.0-smr-feb-2026-r1
Samsung Android=16.0-smr-jan-2026-r1
Samsung Android=16.0-smr-mar-2026-r1
Samsung Android=16.0-smr-nov-2025-r1
Samsung Android=16.0-smr-oct-2025-r1
Samsung Android=16.0-smr-sep-2025-r1
Event History
May 13, 2026
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21021?
CVE-2026-21021 has not been officially assigned a severity rating, but it allows physical attackers to launch privileged activities, indicating a potentially high level of risk.
2
How do I fix CVE-2026-21021?
To mitigate CVE-2026-21021, update to the SMR May-2026 Release 1 or later of Samsung Routines.
3
Who is affected by CVE-2026-21021?
CVE-2026-21021 affects users of Samsung Routines and certain versions of Samsung Android prior to the SMR May-2026 Release 1.
4
What is the nature of the vulnerability in CVE-2026-21021?
CVE-2026-21021 is caused by improper input validation, which can be exploited by physical attackers.
5
Can CVE-2026-21021 be exploited remotely?
CVE-2026-21021 requires physical access to the device for exploitation, so it cannot be exploited remotely.