CVE-2026-21002

CWE-3473 documents3 sources
Severity
5.9MEDIUM
EPSS
0.0%
top 99.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16

Description

Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Packages1 packages

NVDsamsung/galaxy_store< 4.6.03.8

🔴Vulnerability Details

2
CVEList
CVE-2026-21002: Improper verification of cryptographic signature in Galaxy Store prior to version 42026-03-16
GHSA
GHSA-52q6-xhg6-rw2j: Improper verification of cryptographic signature in Galaxy Store prior to version 42026-03-16
CVE-2026-21002 (MEDIUM CVSS 5.9) | Improper verification of cryptograp | cvebase.io