CVE-2026-20994
published 2026-03-16CVE-2026-20994: URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.12%
2.1th percentile
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | account | < 15.5.01.1 | 15.5.01.1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung Samsung Account 1.5.24 Access Token redirect
vuldb·2026-06-01·CVSS 6.9
CVE-2026-20994 [MEDIUM] Samsung Samsung Account 1.5.24 Access Token redirect
A vulnerability, which was classified as problematic, has been found in Samsung Samsung Account 1.5.24. Impacted is an unknown function of the component Access Token Handler. The manipulation leads to open redirect.
This vulnerability is documented as CVE-2026-20994. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-698m-3cpg-fhpm: URL redirection in Samsung Account prior to version 15
ghsa_unreviewed·2026-03-16
CVE-2026-20994 [HIGH] GHSA-698m-3cpg-fhpm: URL redirection in Samsung Account prior to version 15
URL redirection in Samsung Account prior to version 15.5.01.1 allows remote attackers to potentially get access token.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-16
Published