CVE-2026-21037: Samsung Members

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.

Affected products

  • Samsung Members: before 5.8.01.5 (fixed in 5.8.01.5)

Published 2026-06-05. Last modified 2026-06-30.