Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-75940 2026-09-10

CVE-2026-75940: Hardcoded Credentials in Lenovo Health Android App Expose Health Data

"Lenovo disclosed a critical flaw (CVSS 9.1) in its Health Android application for the Chinese market that could let a remote attacker access sensitive health-related information."

Lenovo disclosed a critical flaw (CVSS 9.1) in its Health Android application for the Chinese market that could let a remote attacker access sensitive health-related information.

What Is It

CVE-2026-75940 is a vulnerability reported in the Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information. Lenovo's PSIRT classified the weakness as CWE-798 (Use of Hard-coded Credentials).

The NVD record lists a publication date of 2026-09-10 and a current status of "Deferred." That pairing is unusual, deferral normally follows a period of analysis rather than same-day publication, so the record's metadata may still be settling, and readers should confirm the current status directly at NVD before relying on it. Lenovo assigned a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, and a CVSS 4.0 score of 9.3 (CRITICAL). Both scorings describe a network-reachable issue with low attack complexity that requires no privileges and no user interaction, with high confidentiality and high integrity impact and no availability impact.

Why It Matters

The combination of remote reachability, no authentication, no user interaction, and low complexity means the scoring describes an attack path with little practical barrier between an attacker and the affected data, though the vectors reflect Lenovo's and NVD's assessment rather than a demonstrated exploit. NVD's exploitability subscore is 3.9, the maximum; with an impact subscore of 5.2.

The data at stake is health information, a category that is both personally sensitive and difficult to remediate after disclosure. The high integrity impact in both vector strings suggests the flaw may not be limited to reading data, although neither the NVD entry nor Lenovo's advisory describes the write or modification path in detail.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time. The CVSS 4.0 exploit maturity field is "Not Defined," and no public exploit code is referenced in the source material.

What's Vulnerable

Distribution is limited to the Chinese market, which bounds the exposed population; though users who obtained the app another way, such as by sideloading or through third-party stores, would presumably be affected as well. The advisory does not address that scenario directly.

Patch Status

The supplied NVD record does not state a fixed version or list a patch advisory separate from Lenovo's reference page. Because versions ≤ 1.5.0 are marked affected and the default status is "unaffected," users should consult Lenovo's advisory directly for the remediated build and update to a version above 1.5.0 if one is available. No CISA-mandated required action or due date applies, as the CVE is not in the supplied KEV catalog.

Sources