CVE-2026-21076
Received Received - Intake

Incorrect Authorization in Samsung Health Prior to 7.0.0

Vulnerability report for CVE-2026-21076, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Samsung Mobile

Description

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
samsung samsung_health to 7.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect authorization issue in Samsung Health software versions before 7.0.0. It allows local attackers to bypass access controls and gain unauthorized access to sensitive information stored or processed by the application.

Detection Guidance

This vulnerability involves incorrect authorization in Samsung Health prior to version 7.0.0. To detect it, check the installed version of Samsung Health on affected devices. If the version is below 7.0.0, the system is vulnerable.

Impact Analysis

If you use Samsung Health on an affected device, an attacker with local access could steal personal health data, including fitness metrics, medical information, or other sensitive details stored in the app. This could lead to privacy breaches or identity theft.

Compliance Impact

This vulnerability likely violates data protection requirements under GDPR and HIPAA due to unauthorized access to sensitive personal health information. Organizations using affected Samsung Health versions may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Update Samsung Health to version 7.0.0 or later immediately. Remove or restrict access to vulnerable versions if updates are not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21076. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart