CVE-2026-21037: Input Validation
Published Jun 5, 2026
·Updated
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
Affected Software
2 affected components
Samsung Samsung Members<5.8.01.5
Samsung Members<5.8.01.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung Membersto a version that resolves this vulnerability.Fixed in 5.8.01.5
Event History
Jun 5, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21037?
CVE-2026-21037 has a medium severity rating of 6.9.
2
How do I fix CVE-2026-21037?
To fix CVE-2026-21037, update Samsung Members to version 5.8.01.5 or later.
3
What kind of vulnerability is CVE-2026-21037?
CVE-2026-21037 is classified as an improper input validation vulnerability.
4
Who is affected by CVE-2026-21037?
Users of Samsung Members prior to version 5.8.01.5 are affected by CVE-2026-21037.
5
What can attackers do with CVE-2026-21037?
Attackers can exploit CVE-2026-21037 to access arbitrary URLs and launch activities with Samsung Members privileges.