CVE-2026-20985

Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:members:*:*:*:*:*:*:*:*

History

25 Feb 2026, 18:51

Type Values Removed Values Added
CPE cpe:2.3:a:samsung:members:*:*:*:*:*:*:*:*
Summary
  • (es) Validación de entrada incorrecta en Samsung Members anterior a la versión 5.6.00.11 permite a atacantes remotos conectar una URL arbitraria y lanzar una actividad arbitraria con privilegios de Samsung Members. Se requiere interacción del usuario para activar esta vulnerabilidad.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE NVD-CWE-noinfo
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=02 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=02 - Vendor Advisory
First Time Samsung members
Samsung

04 Feb 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 07:16

Updated : 2026-02-25 18:51


NVD link : CVE-2026-20985

Mitre link : CVE-2026-20985

CVE.ORG link : CVE-2026-20985


JSON object : View

Products Affected

samsung

  • members