Junglewise Threat Intelligence

CVE-2026-21020: Samsung OmaCP improper export of application components

CVE-2026-21020 · Severity: high · CVSS 7.8 · Published 2026-05-13

Vendors: Samsung.

Executive brief

A security vulnerability exists in the OmaCP component on Samsung Android devices, which is responsible for processing network configuration messages. A malicious application installed on the device could exploit this flaw to trigger sensitive system functions that should normally be restricted. This could lead to unauthorized changes to device settings or access to protected data, potentially compromising the device's security and the user's privacy.

Technical details

A vulnerability in the OmaCP (OMA Client Provisioning) application on Samsung Android devices stems from the improper export of application components. By failing to properly restrict access to these components in the Android manifest, the application allows other locally installed apps to interact with its internal interfaces. A local attacker with low privileges can exploit this to invoke privileged functions within the OmaCP context. This could lead to unauthorized configuration changes or elevation of privilege. The issue is resolved in the Samsung SMR May-2026 Release 1 update.

Affected products

  • Samsung Android 14.0 (Samsung devices) Prior to SMR May-2026 Release 1

Timeline

  • 2026-05-13: advisory: Samsung and NVD published the vulnerability details.
  • 2026-05-13: patched: Fix released in Samsung SMR May-2026 Release 1.

References