CVE-2026-20974 Details
Description
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
A vulnerability exists in Samsung Mobile devices running selected Android versions prior to the January 2026 Security Maintenance Release. The issue stems from improper input validation related to network restrictions, which allows physical attackers to bypass the Carrier Relock feature. This vulnerability has been privately disclosed.
Users can apply the January 2026 Security Maintenance Release, which includes the patch for this vulnerability. Details on how to obtain this update can be found on the Samsung Mobile Security Update page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=01 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| samsung android | 13.0 smr-apr-2022-r1 13.0 smr-apr-2023-r1 13.0 smr-apr-2024-r1 13.0 smr-apr-2025-r1 13.0 smr-aug-2022-r1 13.0 smr-aug-2023-r1 13.0 smr-aug-2024-r1 13.0 smr-aug-2025-r1 13.0 smr-dec-2021-r1 13.0 smr-dec-2022-r1 13.0 smr-dec-2023-r1 13.0 smr-dec-2024-r1 13.0 smr-dec-2025-r1 13.0 smr-feb-2022-r1 13.0 smr-feb-2023-r1 13.0 smr-feb-2024-r1 13.0 smr-feb-2025-r1 13.0 smr-jan-2022-r1 13.0 smr-jan-2023-r1 13.0 smr-jan-2024-r1 13.0 smr-jan-2025-r1 13.0 smr-jul-2022-r1 13.0 smr-jul-2023-r1 13.0 smr-jul-2024-r1 13.0 smr-jul-2025-r1 13.0 smr-jun-2022-r1 13.0 smr-jun-2023-r1 13.0 smr-jun-2024-r1 13.0 smr-jun-2025-r1 13.0 smr-mar-2022-r1 13.0 smr-mar-2023-r1 13.0 smr-mar-2024-r1 13.0 smr-mar-2025-r1 13.0 smr-may-2022-r1 13.0 smr-may-2023-r1 13.0 smr-may-2024-r1 13.0 smr-may-2025-r1 13.0 smr-nov-2021-r1 13.0 smr-nov-2022-r1 13.0 smr-nov-2023-r1 13.0 smr-nov-2024-r1 13.0 smr-nov-2025-r1 13.0 smr-oct-2022-r1 13.0 smr-oct-2023-r1 13.0 smr-oct-2024-r1 13.0 smr-oct-2025-r1 13.0 smr-sep-2022-r1 13.0 smr-sep-2023-r1 13.0 smr-sep-2024-r1 13.0 smr-sep-2025-r1 14.0 smr-apr-2022-r1 14.0 smr-apr-2023-r1 14.0 smr-apr-2024-r1 14.0 smr-apr-2025-r1 14.0 smr-aug-2022-r1 14.0 smr-aug-2023-r1 14.0 smr-aug-2024-r1 14.0 smr-aug-2025-r1 14.0 smr-dec-2021-r1 14.0 smr-dec-2022-r1 14.0 smr-dec-2023-r1 14.0 smr-dec-2024-r1 14.0 smr-dec-2025-r1 14.0 smr-feb-2022-r1 14.0 smr-feb-2023-r1 14.0 smr-feb-2024-r1 14.0 smr-feb-2025-r1 14.0 smr-jan-2022-r1 14.0 smr-jan-2023-r1 14.0 smr-jan-2024-r1 14.0 smr-jan-2025-r1 14.0 smr-jul-2022-r1 14.0 smr-jul-2023-r1 14.0 smr-jul-2024-r1 14.0 smr-jul-2025-r1 14.0 smr-jun-2022-r1 14.0 smr-jun-2023-r1 14.0 smr-jun-2024-r1 14.0 smr-jun-2025-r1 14.0 smr-mar-2022-r1 14.0 smr-mar-2023-r1 14.0 smr-mar-2024-r1 14.0 smr-mar-2025-r1 14.0 smr-may-2022-r1 14.0 smr-may-2023-r1 14.0 smr-may-2024-r1 14.0 smr-may-2025-r1 14.0 smr-nov-2021-r1 14.0 smr-nov-2022-r1 14.0 smr-nov-2023-r1 14.0 smr-nov-2024-r1 14.0 smr-nov-2025-r1 14.0 smr-oct-2022-r1 14.0 smr-oct-2023-r1 14.0 smr-oct-2024-r1 14.0 smr-oct-2025-r1 14.0 smr-sep-2022-r1 14.0 smr-sep-2023-r1 14.0 smr-sep-2024-r1 14.0 smr-sep-2025-r1 15.0 smr-apr-2025-r1 15.0 smr-aug-2025-r1 15.0 smr-dec-2025-r1 15.0 smr-feb-2025-r1 15.0 smr-jul-2025-r1 15.0 smr-jun-2025-r1 15.0 smr-mar-2025-r1 15.0 smr-may-2025-r1 15.0 smr-nov-2025-r1 15.0 smr-oct-2025-r1 15.0 smr-sep-2025-r1 16.0 smr-aug-2025-r1 16.0 smr-dec-2025-r1 16.0 smr-nov-2025-r1 16.0 smr-oct-2025-r1 16.0 smr-sep-2025-r1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 2, 2026 | Initial Analysis | [email protected] |
| Jan 9, 2026 | New CVE Received | [email protected] |