CVE-2026-21022: Medium severity Samsung Routines vulnerability
Published May 13, 2026
·Updated
Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
Affected Software
28 affected components
Samsung Routines<SMR May-2026 Release 1
Samsung Android=15.0
Samsung Android=15.0-smr-apr-2025-r1
Samsung Android=15.0-smr-apr-2026-r1
Samsung Android=15.0-smr-aug-2025-r1
Samsung Android=15.0-smr-dec-2025-r1
Samsung Android=15.0-smr-feb-2025-r1
Samsung Android=15.0-smr-feb-2026-r1
Samsung Android=15.0-smr-jan-2025-r1
Samsung Android=15.0-smr-jan-2026-r1
Samsung Android=15.0-smr-jul-2025-r1
Samsung Android=15.0-smr-jun-2025-r1
Samsung Android=15.0-smr-mar-2025-r1
Samsung Android=15.0-smr-mar-2026-r1
Samsung Android=15.0-smr-may-2025-r1
Samsung Android=15.0-smr-nov-2025-r1
Samsung Android=15.0-smr-oct-2025-r1
Samsung Android=15.0-smr-sep-2025-r1
Samsung Android=16.0
Samsung Android=16.0-smr-apr-2026-r1
Samsung Android=16.0-smr-aug-2025-r1
Samsung Android=16.0-smr-dec-2025-r1
Samsung Android=16.0-smr-feb-2026-r1
Samsung Android=16.0-smr-jan-2026-r1
Samsung Android=16.0-smr-mar-2026-r1
Samsung Android=16.0-smr-nov-2025-r1
Samsung Android=16.0-smr-oct-2025-r1
Samsung Android=16.0-smr-sep-2025-r1
Event History
May 13, 2026
CVE Published
via MITRE·04:56 AM
Data Sourced
via MITRE·04:56 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21022?
CVE-2026-21022 is considered a high-severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2026-21022?
To remediate CVE-2026-21022, update your Samsung Routines software to the SMR May-2026 Release 1 or later.
3
Who is affected by CVE-2026-21022?
CVE-2026-21022 affects users of Samsung Routines prior to the SMR May-2026 Release 1.
4
What type of attack does CVE-2026-21022 allow?
CVE-2026-21022 allows local attackers to exploit insufficient permissions to access sensitive information.
5
Is CVE-2026-21022 related to remote vulnerabilities?
No, CVE-2026-21022 is a local vulnerability that requires physical access to the device.