CVE-2026-21014 is an improper access control vulnerability affecting Samsung Camera versions prior to 16.5.00.28 that enables local attackers to access sensitive location data through user interaction. The vulnerability has been assigned a CVSS severity score of 2.8 (LOW) with a local attack vector requiring low complexity and user privileges to exploit. Exploitation requires user interaction to trigger, limiting the attack surface while still enabling unauthorized disclosure of location information. The vulnerability is currently not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation in the wild. With an EPSS score of 0.000130000 and a FAUCET Risk Score of 26.0/100, this represents a low-priority vulnerability with minimal community attention and no publicly available exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.5.00.28CPE matchmatch criteria | cpe:2.3:a:samsung:camera:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.