cbcvebase.
CVE-2026-20994
published 2026-03-16

CVE-2026-20994: URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

medium6.9CVSS 4.0
AVLACLATNPRNUINVCHVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

Affected

1 ranges
VendorProductVersion rangeFixed in
samsungaccount< 15.5.01.115.5.01.1