Description
Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information.
Published: 2026-07-10
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung Health versions earlier than authorization flaw that permits a local attacker to access‑control issue (CWE‑284) that bypasses checks normally required to restrict data access. The result is unauthorized disclosure of device data that could include health metrics, identifiers, or usage statistics.

Affected Systems

Samsung Health for Android, sold by Samsung Mobile. All installations of the app before version 7.00.0.107 are affected and local access.

Risk and Exploitability

The CVSS score of 4.8 reflects moderate severity. With an EPSS score of less than 1%, the probability of exploitation in the wild is very low. The vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale active exploitation. Likely attackers are those with local device access who or physically tamper with the device. No remote exploitation path or privilege escalation is documented.

Generated by OpenCVE AI on July 28, 2026 at 08:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung Health to version 7.00.0.107 or later
  • If an immediate update is not available, uninstall or disable Samsung Health to remove the vulnerable component
  • Enforce device‑level security controls to limit local device access to trusted users

Generated by OpenCVE AI on July 28, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Improper Authorization in Samsung Health Exposes Device Information

Sat, 25 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Local Discovery of Device Information in Samsung Health
Weaknesses CWE-284

Thu, 23 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allows Local Discovery of Device Information in Samsung Health
Weaknesses CWE-284

Sat, 18 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enabling Local Device Information Disclosure in Samsung Health
Weaknesses CWE-284

Thu, 16 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization Enabling Local Device Information Disclosure in Samsung Health

Wed, 15 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Local Device Information Disclosure via Improper Authorization in Samsung Health
Weaknesses CWE-284

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Device Information Disclosure via Improper Authorization in Samsung Health
Weaknesses CWE-284

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allowing Local Access to Connected Device Information in Samsung Health
Weaknesses CWE-284

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization Allowing Local Access to Connected Device Information in Samsung Health
Weaknesses CWE-284

Sat, 11 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health Enables Access to Connected Device Information
Weaknesses CWE-284

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health Enables Access to Connected Device Information
Weaknesses CWE-284

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Health
Vendors & Products Samsung Mobile
Samsung Mobile samsung Health

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information.
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Health
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T13:15:21.288Z

Reserved: 2025-12-11T01:33:35.820Z

Link: CVE-2026-21056

cve-icon Vulnrichment

Updated: 2026-07-10T13:15:12.812Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses