{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-82927","assignerOrgId":"ca193ba2-0cff-4e34-b04e-1ea07103c6fe","state":"PUBLISHED","assignerShortName":"samsung.tv_appliance","dateReserved":"2026-08-31T11:53:17.414Z","datePublished":"2026-09-01T10:42:24.285Z","dateUpdated":"2026-09-21T12:03:58.730Z"},"containers":{"cna":{"providerMetadata":{"orgId":"ca193ba2-0cff-4e34-b04e-1ea07103c6fe","shortName":"samsung.tv_appliance","dateUpdated":"2026-09-21T12:03:58.730Z"},"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-822","description":"CWE-822 Untrusted pointer dereference","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-129","descriptions":[{"lang":"en","value":"CAPEC-129 Pointer Manipulation"}]}],"affected":[{"vendor":"Samsung Open Source","product":"mTower","versions":[{"status":"affected","version":"0","lessThan":"06994e303637512e39062f3e037c222e8448e57e","versionType":"git"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.\n\nThis issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.","supportingMedia":[{"type":"text/html","base64":false,"value":"Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation.<p>This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.</p>"}]}],"references":[{"url":"https://github.com/Samsung/mTower/pull/250"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseSeverity":"MEDIUM","baseScore":5.5,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}}],"credits":[{"lang":"en","value":"We would like to thank Tijs Bellefroid, Antonis Louka, Marton Bognar, and Jo Van Bulck from DistriNet, KU Leuven for reporting this vulnerability to the Samsung Product Security Incident Response Team  (PSIRT).","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-01T12:18:11.507844Z","id":"CVE-2026-82927","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-01T12:18:27.300Z"}}]}}