Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
CVE-2026-20994: Samsung Account URL Redirection Allows Local Attack
CVE-2026-20994 · published 5 months ago
Summary
A security flaw in Samsung Account software prior to version 15.5.01.1 allows an attacker on the same local network to potentially obtain an access token. This could be used to access sensitive information or take control of the account. To fix this issue, update Samsung Account to the latest version.
What to do
- Update samsung account to version 15.5.01.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| samsung | account |
< 15.5.01.1 cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:* |
Original advisory text
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
Severity
6.9
Medium
CVSS 4.0: 6.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-601Open Redirect
Timeline
Published16 Mar 2026
Updated15 Jun 2026
First seen20 May 2026
Sources
CVE-2026-20994 · NVD
Monitor software like this
Free during beta