CVE-2026-21099: SettingsProvider vulnerability
Published Sep 9, 2026
·Updated
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
Affected Software
1 affected component
SettingsProvider<SMR Sep-2026 Release 1
Event History
Sep 9, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local access to the affected device. The provided information does not indicate that it can be exploited remotely.
2
What is exposed if the issue is exploited?
The issue allows access to sensitive information. The specific information types and affected SettingsProvider configurations are not identified in the provided data.
3
Which update addresses the issue?
The issue affects SettingsProvider before SMR Sep-2026 Release 1. Updating to that release or a later release addresses the stated affected range.