CVE-2026-20985
MEDIUMSamsung Members <5.6.00.11 - SSRF
Title source: llmDescription
Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.
Scores
CVSS v3
4.3
EPSS
0.0003
EPSS Percentile
6.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Classification
Status
published
Affected Products (1)
samsung/members
< 5.6.00.11
Timeline
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026