Reference data/CVE/CVE-2026-49509

CVE-2026-49509

MediumReceivedScore 4.4 · CVSS v3.1
Published: 4 Sept 2026, 00:17Modified: 4 Sept 2026, 06:16Source: PSIRT@samsung.com

Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.

Weaknesses (CWE):CWE-125

CVSS v3.1

Current4.4MEDIUMPSIRT@samsung.com

AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Attack Vector

LocalAV:L

Attack Complexity

LowAC:L

Privileges Required

NonePR:N

User Interaction

RequiredUI:R

Scope

UnchangedS:U

Confidentiality Impact

LowC:L

Integrity Impact

NoneI:N

Availability Impact

LowA:L

CVSS temporel

Estimation3.9

E:U/RL:U/RC:R

Temporal score updated on 4 Sept 2026, 07:36

Source: PatchCVE heuristic estimate (CISA KEV, EPSS from FIRST.org, NVD reference tags, NVD status) — not published by a CNA.

Exploit Code Maturity

UnprovenE:U

No known exploit

No known exploit: absent from CISA KEV and exploit-db, no reference tagged Exploit, SSVC reports no exploitation — Unproven

Remediation Level

UnavailableRL:U

No reference tagged as fix or vendor advisory found

Report Confidence

ReasonableRC:R

NVD status: Received

References — 3