Description
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung Health prior to version 7.0.0 is vulnerable to a relative path traversal flaw, allowing an attacker who can execute code on the device to read files outside the intended application directory. This results in the disclosure of sensitive user information stored on the device, compromising confidentiality. The weakness is a classic path traversal issue.

Affected Systems

The affected product is Samsung Health on Samsung Mobile devices. Versions earlier than 7.0.0 are impacted; no specific patch release versions are listed beyond this threshold.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating a medium severity impact. EPSS data is not available, but the flaw requires local execution or access to the device, so remote exploitation is unlikely. It is not listed in the CISA KEV catalog, suggesting that no widespread exploitation has been reported yet. Nevertheless, once on a device an attacker can read arbitrary files, so the potential for data compromise remains significant.

Generated by OpenCVE AI on August 10, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung Health to version 7.0.0 or later to remove the path traversal bug
  • If an update is not immediately available, control the app’s file read permissions at the operating system level or restrict the app to a sandboxed environment
  • Regularly audit device storage for unexpected files and monitor application logs for unauthorized file access attempts

Generated by OpenCVE AI on August 10, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Health
Vendors & Products Samsung Mobile
Samsung Mobile samsung Health

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Relative Path Traversal in Samsung Health Allowing Local Access to Sensitive Information
Weaknesses CWE-22

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Health
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T07:44:01.122Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21082

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T10:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')