Junglewise Threat Intelligence

CVE-2026-5462: Wahoo Fitness SYSTM App hard-coded cryptographic key in BuildConfig

CVE-2026-5462 · Severity: low · CVSS 3.3 · Published 2026-04-03

Executive brief

A security vulnerability exists in the Wahoo Fitness SYSTM app for Android, a training platform for athletes. The application contains a hard-coded security key within its internal configuration files. A person with physical or local access to the device could potentially use this key to access or manipulate user profile data and inject unauthorized information into the system.

Technical details

A vulnerability (CWE-321) exists in the Wahoo Fitness SYSTM App for Android up to version 7.2.1. The application exposes a hard-coded cryptographic key, specifically the 'SEGMENT_WRITE_KEY', within the 'com/WahooFitness/SYSTM/BuildConfig.java' file. An attacker with local access to the device can extract this key to perform unauthorized data injection or manipulate user profiles via the Segment analytics integration. While the vendor was notified, no patch has been confirmed at the time of disclosure. A public exploit is reportedly available.

Affected products

  • Wahoo Fitness SYSTM App up to 7.2.1

Timeline

  • 2026-04-03: disclosed
  • 2026-04-03: advisory

References