CyberRota Analysis
AI-GeneratedImproper access control in the Settings of affected products prior to the SMR Jul-2026 Release 1 enables local attackers to manipulate Theft protection settings, potentially compromising device security. Organizations utilizing these products should prioritize addressing this vulnerability to prevent unauthorized configuration changes that could lead to theft or data loss.
CVE
CVE-2026-21039
Severity
MEDIUM
CVSS
6.9
EPSS
0.10%
Original NVD Description
Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.