PatchSiren

Wahoo Fitness CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Wahoo Fitness CVE published 2026-04-03

CVE-2026-5462

A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android, involving a hard-coded cryptographic key in the file com/WahooFitness/SYSTM/BuildConfig.java of the component com.WahooFitness.SYSTM. Local access is required to approach this attack. The exploit is publicly available. This issue has a low CVSS score of 1.9, indicating a low severity vulnerability. The vulnerability affects [truncated]