Junglewise Threat Intelligence

CVE-2026-75940: Lenovo Health Android Application information disclosure vulnerability

CVE-2026-75940 · Severity: critical · CVSS 9.1 · Published 2026-09-10

Vendors: Lenovo.

Executive brief

Lenovo Health is a health-tracking application distributed in the Chinese market. A vulnerability in the app could allow attackers to access sensitive health-related information, including personal medical data and wellness records, potentially exposing private health conditions and patient history.

Technical details

A vulnerability exists in the Lenovo Health Android application that permits unauthorized access to sensitive health-related information. The vulnerability is likely an information disclosure flaw that could stem from inadequate access controls, insecure data storage, or exposed API endpoints. The attack vector appears to be network-based without requiring authentication or special privileges. Exploitation could result in exposure of personal health data, including medical history, wellness metrics, and potentially personally identifiable information (PII). Patch or remediation details were not available in the provided advisory.

Affected products

  • Lenovo Health Android Application <UNKNOWN>

Timeline

  • 2026-09-10: disclosed

References