Description
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.
Published: 2026-09-10
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure
Action: Patch
AI Analysis

Impact

The vulnerability in the Lenovo Health Android Application permits an attacker to read sensitive health flaw arises from the use of hard‑coded credentials, identified as CWE‑798, allowing the retrieval of personal health data and raising significant privacy concerns.

Affected Systems

Lenovo Health Android Application, distributed only in the Chinese market. Versions prior to 1.5.0 are vulnerable; the vendor recommends upgrading to 1.5.0 or later.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity risk of data exposure. The EPSS score is not available and the vulnerability is not listed in the KEV catalog, suggesting no widespread exploitation has been reported yet. Attack access is not explicitly disclosed in the advisory; it is inferred that an attacker could exploit the installed application itself, potentially through local use or via a remote trigger. Consequently, the likelihood of exploitation depends on device.

Generated by OpenCVE AI on September 11, 2026 at 04:50 UTC.

Remediation

Vendor Solution

Update Lenovo Health Android Application version to 1.5.0 or later.


OpenCVE Recommended Actions

  • Apply the official vendor update to Lenovo Health Android Application version 1.5.0 or possible, limit the app’s data sharing and location permissions, disabling any unnecessary permissions on older devices.
  • Monitor Android system logs for suspicious outbound connections from the Health app and consider deploying a mobile security solution to block unauthorized data exfiltration.
  • If an update cannot be applied, uninstall the Lenovo Health Android Application to eliminate the data exposure source.

Generated by OpenCVE AI on September 11, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Hard‑coded Credentials Enable Access to Personal Health Information

Fri, 11 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Hard‑coded Credentials Enable Access to Personal Health Information

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.
First Time appeared Lenovo
Lenovo health Application
Weaknesses CWE-798
CPEs cpe:2.3:a:lenovo:health_application:*:*:android:*:*:*:*:*
Vendors & Products Lenovo
Lenovo health Application
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Health Application
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-09-11T14:50:16.336Z

Reserved: 2026-08-18T15:55:52.564Z

Link: CVE-2026-75940

cve-icon Vulnrichment

Updated: 2026-09-11T14:50:11.189Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:44.080

Modified: 2026-09-11T15:17:03.967

Link: CVE-2026-75940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:10Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials