Junglewise Threat Intelligence

CVE-2026-21103: Samsung GalaxyDiagnostics path traversal

CVE-2026-21103 · Severity: medium · CVSS 6.1 · Published 2026-09-09

Vendors: Samsung.

Executive brief

GalaxyDiagnostics is a diagnostic tool used in Samsung devices. A path traversal vulnerability allows an attacker with physical access to the device to read or modify files with system-level privileges, potentially exposing sensitive data or enabling further compromise.

Technical details

This is a path traversal vulnerability in Samsung GalaxyDiagnostics prior to the SMR Sep-2026 Release 1 patch. The vulnerability allows an attacker with physical access to bypass directory restrictions and access files with system privilege by manipulating path inputs. The attack requires physical access to the affected device, which limits the attack surface to scenarios where an attacker has hands-on device access. The vulnerability has been patched in the September 2026 security update.

Affected products

  • Samsung GalaxyDiagnostics prior to SMR Sep-2026 Release 1

Timeline

  • 2026-09-09: disclosed
  • 2026-09: patched: Fixed in SMR Sep-2026 Release 1

References