CVE-2026-6839 is an improper input validation vulnerability in Samsung Open Source ONE that allows malformed string metadata to trigger out-of-bounds memory access when importing constant tensors with invalid STRING tensor offsets. This flaw affects all versions prior to commit 1.30.0 and could enable denial of service or information disclosure attacks. The vulnerability has a CVSS score of 6.6 (Medium severity) with a local attack vector requiring no privileges but user interaction to trigger. While the attack complexity is low, the impact includes partial confidentiality loss, partial integrity compromise, and significant availability disruption through the out-of-bounds access. The vulnerability is not currently being actively exploited in the wild, as it does not appear on the Known Exploited Vulnerabilities catalog. The EPSS score of 0.00018 indicates minimal real-world exploitation probability compared to other CVEs. However, organizations using Samsung Open Source ONE should apply the patch to version 1.30.0 or later to mitigate this local attack risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.0CPE matchmatch criteria | cpe:2.3:a:samsung:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.