Junglewise Threat Intelligence

CVE-2026-21092: Samsung ImsService path traversal in SMR Sep-2026

CVE-2026-21092 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Vendors: Samsung.

Executive brief

Samsung's ImsService, a core component handling multimedia messaging on Android devices, contains a path traversal vulnerability that allows remote attackers to create files with system-level privileges. An attacker could exploit this to write malicious files to arbitrary locations on the device, potentially enabling code execution or persistent compromise of the device.

Technical details

The vulnerability is a path traversal flaw in ImsService that exists prior to the Samsung Monthly Release (SMR) September 2026 patch. The vulnerability allows remote attackers to specify arbitrary file paths and create image files with system server privilege, bypassing normal file permission restrictions. The attack vector is network-based and does not require authentication or user interaction. An attacker can achieve arbitrary file creation on the affected device, which in combination with system privileges could lead to code execution or system compromise. The fix is available in SMR Sep-2026 Release 1 and later.

Affected products

  • Samsung ImsService prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: Fix available in SMR Sep-2026 Release 1

References