CVE-2026-21092
8.8Samsung · Samsung Mobile Devices
A path traversal vulnerability in the ImsService of Samsung Mobile Devices allows unauthenticated remote attackers to create files with system server privileges.
Executive summary
A high-severity path traversal vulnerability in Samsung Mobile Devices allows unauthenticated remote attackers to achieve unauthorized file creation with elevated privileges.
Vulnerability
This flaw is a path traversal vulnerability (CWE-35) located in the ImsService component, which can be triggered by an unauthenticated remote attacker to create image files within the system server context.
Business impact
The ability for an unauthenticated attacker to write files with system server privileges poses a significant risk to device integrity and security. Successful exploitation could lead to unauthorized system modification, potential privilege escalation, or the injection of malicious assets, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Update all affected Samsung mobile devices to the SMR Sep-2026 Release 1 or later versions as specified in the official Samsung security advisory.
Proactive Monitoring: Review device logs for unusual file system write operations or unexpected activity originating from the ImsService component.
Compensating Controls: Ensure that third-party applications are restricted from accessing sensitive system directories and maintain up-to-date mobile device management (MDM) policies to enforce security configurations.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for system-level file creation, this vulnerability represents a significant risk to the mobile ecosystem. Organizations and individual users should prioritize applying the SMR Sep-2026 security updates to all supported Samsung devices to mitigate the risk of unauthorized system access.
More Samsung CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section