Lenovo Health Android Application, distributed exclusively in the Chinese market
Lenovo Health for Android could let a remote attacker access sensitive health information. The app was distributed exclusively in China.
- Severity
- CriticalCVSS 3.1 · 9.1
- Fix
- Not confirmedLast checked today
- Affected versions
- through 1.5.0
- Weakness
- CWE-798Use of Hard-coded Credentials
- Exploit likelihood
- 0.29% in 30 daysEPSS, higher than 21% of known flaws
- Affects
- Health Application
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-75749ENISA vulnerability database
How it works
- The record identifies hard-coded credentials in Lenovo Health for Android.
- It says the flaw is reachable over a network without login or user action.
- Public evidence does not explain the exact data-access path.
What to do
Check the Lenovo Health app version on your Android device and compare it with the CVE record. The record's version boundaries conflict, so treat the exact cutoff as unresolved.
Technical details
Affected software: Health Applicationby Lenovo
CVE-2026-75940 concerns hard-coded credentials in Lenovo Health Android Application. Its CVSS records describe network access without authentication or user interaction, with high confidentiality and integrity impact but no availability impact.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Open in FIRST.org calculatorReferences
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-75940 third party advisory vdb entry
- cvefeed.io · CVE-2026-75940 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-75940
- iknow.lenovo.com.cn · 442248 vendor-advisory NVD