Description
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Published: 2026-08-10
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Samsung Health before version 7.0.0 contains a relative path traversal vulnerability that exposes sensitive data to unauthenticated local users. The CVE does not specify how the flaw is triggered, but a user or process with local access could cause the application to read files outside its intended directory, potentially revealing personal health records and other confidential information. The weakness is a classic path traversal flaw.

Affected Systems

The affected product is Samsung Health on Samsung Mobile devices. Versions earlier than 7.0.0 are impacted; no specific patch release versions are listed beyond this threshold.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating a medium severity impact. EPSS score is reported as < 1%, reflecting a very low but non-zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, suggesting no widespread exploitation. Based on the description, the exact attack vector is not specified, but the vulnerability implies that local access is needed to exploit the path traversal. Deployment in a local context could allow an attacker with device access to read arbitrary files, thereby compromising confidentiality, though remote exploitation is unlikely based on current information.

Generated by OpenCVE AI on August 10, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Samsung Health to version 7.0.0 or later to remove the path traversal bug
  • If an update is not immediately available, control the app’s file read permissions at the operating system level or restrict the app to a sandboxed environment
  • Regularly audit device storage for unexpected files and monitor application logs for unauthorized file access attempts

Generated by OpenCVE AI on August 10, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Samsung
Samsung health
CPEs cpe:2.3:a:samsung:health:*:*:*:*:*:*:*:*
Vendors & Products Samsung
Samsung health
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Mon, 10 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in Samsung Health Exposes Sensitive Data

Mon, 10 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Relative Path Traversal in Samsung Health Allowing Local Access to Sensitive Information
Weaknesses CWE-22

Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-23
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Health
Vendors & Products Samsung Mobile
Samsung Mobile samsung Health

Mon, 10 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Relative Path Traversal in Samsung Health Allowing Local Access to Sensitive Information
Weaknesses CWE-22

Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Health
Samsung Mobile Samsung Health
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-08-10T17:39:56.946Z

Reserved: 2025-12-11T01:33:35.825Z

Link: CVE-2026-21082

cve-icon Vulnrichment

Updated: 2026-08-10T17:39:41.574Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-10T09:17:21.920

Modified: 2026-08-19T16:31:07.750

Link: CVE-2026-21082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:00:07Z

Weaknesses
  • CWE-23

    Relative Path Traversal