CVE-2026-21075: Medium severity My Galaxy vulnerability
Published Aug 10, 2026
·Updated
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
Affected Software
1 affected component
My Galaxy<6.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
My Galaxyto a version that resolves this vulnerability.Fixed in 6.3
Event History
Aug 10, 2026
CVE Published
via MITRE·07:42 AM
Data Sourced
via MITRE·07:42 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-21075?
CVE-2026-21075 has a risk rating of 52, indicating a moderate severity level.
2
How do I fix CVE-2026-21075?
To fix CVE-2026-21075, update My Galaxy to version 6.3 or later.
3
What information can be accessed due to CVE-2026-21075?
CVE-2026-21075 allows remote attackers to access sensitive information through improper authorization.
4
Which versions of My Galaxy are affected by CVE-2026-21075?
My Galaxy versions prior to 6.3 are affected by CVE-2026-21075.
5
Who is at risk due to CVE-2026-21075?
Users of My Galaxy prior to version 6.3 are at risk due to CVE-2026-21075.