CVE-2026-20982
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
- Samsung Android
- = 14.0, 15.0, 16.0
- CVSS 4.0
- 6.8 MEDIUM
- CVSS 3.1
- 6.0 MEDIUM
- EPSS
- 0.3% (23th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-02-04
CVE-2026-20982 at NVD
2 known exploits for CVE-2026-20982
Proof-of-concept code and exploit modules indexed by Sploitus