← Vulnerability feed

Vulnerability record · CVE-2026-20985 · published 4 February 2026

CVE-2026-20985: Samsung members vulnerability

Samsung · Members

Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

7.0 CVSS 4.0 High EPSS 0.29% · top 80.4%
7.0CVSS 4.0 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20985 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2025-20949Samsung members path traversal vulnerabilityPath traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Sa…EPSS 0.32%8.1CVE-2025-21079Samsung members vulnerabilityImproper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity…EPSS 0.54%7.8CVE-2021-25438Samsung members improper access control vulnerabilityImproper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and…EPSS 1.7%7.5CVE-2021-25374Samsung members improper authorization vulnerabilityAn improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and…EPSS 3.1%6.9CVE-2026-21037Samsung members vulnerabilityImproper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity w…EPSS 0.11%5.5CVE-2022-30748Samsung members vulnerabilityUnprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.EPSS 0.22%5.1CVE-2026-20986Samsung members path traversal vulnerabilityPath traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.EPSS 0.16%4.6CVE-2025-20898Samsung members vulnerabilityImproper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles.EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2026-20985), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.