Description
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization logic within Samsung Health that allows a local attacker to view personal health information. It is an improper authorization flaw, identified as CWE‑863, which can lead to exposure of confidential data such as medical records or personal metrics. The impact is the loss of confidentiality for users who rely on the app to store or manage private health data.

Affected Systems

Samsung Health on Samsung Mobile devices running any version prior to 7.0.0 is affected. The issue is present in all releases before the 7.0.0 update, regardless of device model or Android version, as the authorization check is performed inside the app itself.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, reflecting that the flaw does not allow remote code execution but can subvert data privacy. The EPSS score is reported as less than 1%, indicating a very low likelihood of active exploitation, and the absence of a KEV listing suggests it has not yet been widely exploited. The attack vector is local; an attacker must have physical or device‑access privileges, such as a renter or someone with temporary access to a device. Once local access is achieved, the authorization bypass exposes private health data to the attacker.

Generated by OpenCVE AI on August 10, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Health to version 7.0.0 or newer, which includes the fixed authorization logic.
  • If an upgrade is not immediately possible, restrict the app's permissions to prevent local data access or use device‑level restrictions (e.g., device administration or parental controls) to limit physical access.
  • Consider disabling or limiting sharing features within the app until the patch is applied to reduce the risk of data exposure to other apps or services.
  • Monitor device security logs for unusual activity that could indicate a local data extraction attempt.

Generated by OpenCVE AI on August 10, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung health
CPEs cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung health
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Mon, 10 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health Allows Access to Sensitive Personal Data

Mon, 10 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health App
Weaknesses CWE-285

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health App
First Time appeared Samsung Mobile
Samsung Mobile samsung Health
Weaknesses CWE-285
Vendors & Products Samsung Mobile
Samsung Mobile samsung Health

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Health
Samsung Mobile Samsung Health
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:18:57.670Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21076

cve-icon Vulnrichment

Updated: 2026-08-10T17:17:23.159Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-10T09:17:21.153

Modified: 2026-08-19T17:10:57.447

Link: CVE-2026-21076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:00:07Z

Weaknesses