CVE-2026-21028: Medium severity Samsung AuditLogService vulnerability
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AuditLogServiceto a version that resolves this vulnerability.Fixed in SMR Jun-2026 Release 1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21028?
CVE-2026-21028 has a medium severity rating of 5.1 according to the CVSS score.
How do I fix CVE-2026-21028?
To fix CVE-2026-21028, update to the latest version of the Samsung AuditLogService released post June 2026.
What vulnerabilities does CVE-2026-21028 exploit?
CVE-2026-21028 exploits improper access control allowing local attackers to access sensitive information.
Who is affected by CVE-2026-21028?
Users of the Samsung AuditLogService prior to the SMR Jun-2026 Release 1 are affected by CVE-2026-21028.
What is the potential impact of CVE-2026-21028?
The potential impact of CVE-2026-21028 is unauthorized access to sensitive information by local attackers.