SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-21099

MEDIUM · CVSS 5.5 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Improper access control in the SettingsProvider component prior to the SMR Sep-2026 Release 1 allows local attackers to exploit this vulnerability and gain unauthorized access to sensitive information. Organizations utilizing affected products should prioritize remediation efforts to mitigate the risk of data exposure from local threats. This vulnerability is particularly relevant for environments where sensitive data is handled and local access is possible.

CVE
CVE-2026-21099
Severity
MEDIUM
CVSS
5.5
EPSS
0.09%

Original NVD Description

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Related CVEs

Other vulnerabilities affecting the same vendor(s)