← Vulnerability feed

Vulnerability record · CVE-2026-20998 · published 16 March 2026

CVE-2026-20998: Samsung smart switch vulnerability

Samsung · Smart Switch

Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

7.1 CVSS 4.0 High EPSS 0.55% · top 56.4%
7.1CVSS 4.0 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20998 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-21062Samsung smart switch broken cryptographic algorithm vulnerabilityUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring applicatio…EPSS 0.10%7.1CVE-2026-21005Samsung smart switch path traversal vulnerabilityPath traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.EPSS 0.24%7.1CVE-2026-20996Samsung smart switch broken cryptographic algorithm vulnerabilityUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme …EPSS 0.17%7.1CVE-2026-20999Samsung smart switch authentication bypass by capture-replay vulnerabilityAuthentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.EPSS 0.31%7.0CVE-2026-21079Samsung smart switch missing encryption vulnerabilityMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.EPSS 0.10%6.9CVE-2026-21080Samsung smart switch cleartext storage of sensitive data vulnerabilityCleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.17%6.9CVE-2026-21004Samsung smart switch improper authentication vulnerabilityImproper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.EPSS 0.19%6.8CVE-2026-21083Samsung smart switch improper input validation vulnerabilityImproper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-20998), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.