CVE-2026-21037
published 2026-06-05CVE-2026-21037: Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with…
PriorityP335high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.10%
1.3th percentile
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | members | < 5.8.01.5 | 5.8.01.5 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Samsung Members up to 5.6.00.11 input validation (EUVD-2026-34809)
vuldb·2026-07-03·CVSS 7.1
CVE-2026-21037 [HIGH] Samsung Members up to 5.6.00.11 input validation (EUVD-2026-34809)
A vulnerability classified as problematic has been found in Samsung Members up to 5.6.00.11. The affected element is an unknown function. Performing a manipulation results in improper input validation.
This vulnerability was named CVE-2026-21037. The attack needs to be approached locally. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
ghsa_unreviewed·2026-06-05
CVE-2026-21037 [MEDIUM] Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-05
Published