Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-apr\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-aug\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-dec\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-feb\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-jul\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-jun\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-mar\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-may\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-nov\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-oct\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0-smr\\-sep\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0-smr\\-aug\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0-smr\\-dec\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0-smr\\-nov\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0-smr\\-oct\\-2025\\-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.0-smr\\-sep\\-2025\\-r1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-20970.json"