{"id":"CVE-2026-21106","title":"Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.","summary":"Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-925"],"vendor":"Samsung Mobile","product":"Samsung Cloud Assistant","affected":["samsung_cloud_assistant (all versions)"],"published":"2026-09-09","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:17:28.737","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21106","references":[{"url":"https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09","label":"mobile.security@samsung.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T14:13:54.190865Z"},"cvssSource":"cna","ingestedAt":"2026-09-14T04:36:54.926Z","epss":0.00105,"epssPercentile":0.00983,"slug":"CVE-2026-21106","body":"## Overview\n\nImproper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}