CVE-2026-21084: Medium severity SmartThings SmartThings vulnerability
Published Aug 10, 2026
·Updated
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
Affected Software
1 affected component
SmartThings SmartThings<1.8.47.24
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SmartThingsto a version that resolves this vulnerability.Fixed in 1.8.47.24
Event History
Aug 10, 2026
CVE Published
via MITRE·07:44 AM
Data Sourced
via MITRE·07:44 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-21084?
CVE-2026-21084 has a risk rating of 27, indicating a moderate severity level.
2
How do I fix CVE-2026-21084?
To mitigate CVE-2026-21084, upgrade SmartThings to version 1.8.47.24 or later.
3
What type of vulnerability is CVE-2026-21084?
CVE-2026-21084 is classified as an improper access control vulnerability.
4
Who can be affected by CVE-2026-21084?
Local attackers can exploit CVE-2026-21084 to access sensitive information.
5
Which software versions are vulnerable to CVE-2026-21084?
SmartThings versions prior to 1.8.47.24 are vulnerable to CVE-2026-21084.