CyberRota Analysis
AI-GeneratedImproper access control in the SettingsProvider component prior to the SMR Sep-2026 Release 1 allows local attackers to exploit this vulnerability and gain unauthorized access to sensitive information. Organizations utilizing affected products should prioritize remediation efforts to mitigate the risk of data exposure from local threats. This vulnerability is particularly relevant for environments where sensitive data is handled and local access is possible.
CVE
CVE-2026-21099
Severity
MEDIUM
CVSS
5.5
EPSS
0.09%
Original NVD Description
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
Related CVEs
Other vulnerabilities affecting the same vendor(s)