Description
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization in Samsung Health before version 7.0.0, a weakness that falls under CWE‑863: Incorrect Authorization. This flaw permits any local attacker with access to the device to bypass authorization controls and read protected health data stored by the app, resulting in a confidentiality breach.

Affected Systems

Samsung Mobile Samsung Health applications installed on Android devices running any version earlier than 7.0.0. The flaw is present in all pre‑7.0.0 builds as indicated by the vendor information. No specific device models are listed; all Samsung Health users with older versions are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score indicates a very low exploitation probability (< 1%). The vulnerability is not listed in the CISA KEV catalog. The attack requires local possession of the device; an attacker could invoke the app’s functions or inject malicious code into the device to read data. Because the flaw is limited to local execution, the risk is confined to the device owner or anyone with physical/local access, but the sensitive nature of the data makes it a significant concern.

Generated by OpenCVE AI on August 10, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung Health to version 7.0.0 or later to eliminate the incorrect authorization check.
  • If an update is not available, uninstall the Samsung Health app to prevent local attackers from accessing the data.
  • Enforce device‑level security such as strong passwords, biometric authentication, and limit local access to trusted users to reduce the likelihood that a local attacker can exploit the flaw.

Generated by OpenCVE AI on August 10, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung health
CPEs cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung health
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Mon, 10 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health Pre‑7.0.0 Exposes Sensitive Data

Mon, 10 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health Allows Access to Sensitive Information
Weaknesses CWE-284

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Health
Vendors & Products Samsung Mobile
Samsung Mobile samsung Health

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Samsung Health Allows Access to Sensitive Information
Weaknesses CWE-284

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Health
Samsung Mobile Samsung Health
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:19:55.227Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21077

cve-icon Vulnrichment

Updated: 2026-08-10T17:19:36.442Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-10T09:17:21.283

Modified: 2026-08-19T16:32:24.960

Link: CVE-2026-21077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:30:07Z

Weaknesses