CVE-2026-21023
published 2026-04-29CVE-2026-21023: Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.10%
1.2th percentile
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | android | — | — |
| samsung | android | — | — |
| samsung | android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung Devices PackageManagerService data authenticity (EUVD-2026-26192 / CNNVD-202604-5697)
vuldb·2026-05-04·CVSS 6.9
CVE-2026-21023 [MEDIUM] Samsung Devices PackageManagerService data authenticity (EUVD-2026-26192 / CNNVD-202604-5697)
A vulnerability has been found in Samsung Devices and classified as critical. Affected by this issue is some unknown functionality of the component PackageManagerService. This manipulation causes insufficient verification of data authenticity.
This vulnerability is tracked as CVE-2026-21023. The attack is restricted to local execution. No exploit exists.
It is suggested to install a patch to address this issue.
GHSA
GHSA-pg82-7v49-4hr5: Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installat
ghsa_unreviewed·2026-04-29
CVE-2026-21023 [MEDIUM] GHSA-pg82-7v49-4hr5: Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installat
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-29
Published