Medium severityNVD Advisory· Published Jun 5, 2026· Updated Jun 5, 2026
CVE-2026-21028
CVE-2026-21028
Description
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Affected products
1- Range: < SMR Jun-2026 Release 1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Samsung Mobile: 21 Medium-Severity Vulnerabilities Disclosed in June 2026Vypr Intelligence · Jun 5, 2026