GalaxyDiagnostics <3.5.050 Improper Input Validation Enables Local Privileged Command Execution
CVE-2026-20987 Published on February 4, 2026
Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.
Affected Versions
Samsung Mobile GalaxyDiagnostics Version 3.5.050 is unaffected by CVE-2026-20987Exploit Probability
EPSS
0.01%
Percentile
0.37%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.