SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-21039

MEDIUM · CVSS 6.9 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Improper access control in the Settings of affected products prior to the SMR Jul-2026 Release 1 enables local attackers to manipulate Theft protection settings, potentially compromising device security. Organizations utilizing these products should prioritize addressing this vulnerability to prevent unauthorized configuration changes that could lead to theft or data loss.

CVE
CVE-2026-21039
Severity
MEDIUM
CVSS
6.9
EPSS
0.10%

Original NVD Description

Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.