2.1
/ 10
LOW
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Description
Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.
Basic Information
ID
CVE-2026-20975
Source
SamsungMobile
Published
Jan 9, 2026 at 06:16
Affected Product
Vendor
Samsung Mobile
Product
Samsung Cloud
Version
5.6.11