CVE-2026-20994

URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:*

History

29 May 2026, 19:22

Type Values Removed Values Added
References () https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=03 - () https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=03 - Vendor Advisory
CPE cpe:2.3:a:samsung:account:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Samsung
Samsung account

20 May 2026, 04:16

Type Values Removed Values Added
CWE CWE-601
Summary
  • (es) Redirección de URL en Samsung Account anterior a la versión 15.5.01.1 permite a atacantes remotos obtener potencialmente un token de acceso.
Summary (en) URL redirection in Samsung Account prior to version 15.5.01.1 allows remote attackers to potentially get access token. (en) URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

16 Mar 2026, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:18

Updated : 2026-05-29 19:22


NVD link : CVE-2026-20994

Mitre link : CVE-2026-20994

CVE.ORG link : CVE-2026-20994


JSON object : View

Products Affected

samsung

  • account
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')