CVE-2026-21074: High severity Bixby vulnerability
Published Aug 10, 2026
·Updated
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.
Affected Software
1 affected component
Bixby<4.0.86.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bixbyto a version that resolves this vulnerability.Fixed in 4.0.86.0
Event History
Aug 10, 2026
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-21074?
The severity of CVE-2026-21074 is rated as risk 46.
2
What does CVE-2026-21074 exploit?
CVE-2026-21074 exploits incorrect default permissions in Bixby allowing local attackers to execute arbitrary commands.
3
How do I fix CVE-2026-21074?
To fix CVE-2026-21074, update Bixby to version 4.0.86.0 or later.
4
Who is affected by CVE-2026-21074?
Users of Bixby prior to version 4.0.86.0 are affected by CVE-2026-21074.
5
What kind of attacks can CVE-2026-21074 facilitate?
CVE-2026-21074 can facilitate local attacks enabling arbitrary command execution with Bixby privileges.