CVE-2026-20981
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
- Samsung Android
- = 14.0, 15.0, 16.0
- CVSS 3.1
- 6.6 MEDIUM
- EPSS
- 0.2% (10th percentile)
- NVD status
- Analyzed
- Published
- 2026-02-04
CVE-2026-20981 at NVD
2 known exploits for CVE-2026-20981
Proof-of-concept code and exploit modules indexed by Sploitus