CVE-2026-20987 describes an improper input validation vulnerability in GalaxyDiagnostics versions prior to 3.5.050, allowing local privileged attackers to execute privileged commands. This vulnerability carries a high CVSS score of 8.7, indicating a significant risk due to its low attack complexity and the potential for high impact across confidentiality, integrity, and availability. While the vulnerability requires privileged access, a successful exploit could lead to complete system compromise. Currently, there is no evidence of active exploitation, and no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Samsung Mobile | GalaxyDiagnostics | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.