CVE-2026-20994: Samsung Account

Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.

URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

Affected products

  • Samsung Account: before 15.5.01.1 (fixed in 15.5.01.1)

Published 2026-03-16. Last modified 2026-06-17.