Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Health application PumpUp server puts 6 million users information at risk
  • Data Leak

Health application PumpUp server puts 6 million users information at risk

Do Son June 5, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

According to ZDNet report, PumpUp in Ontario, Canada, issued a statement last week that its social health tracking application under the same name inadvertently exposed the user’s privacy and sensitive data, including health information and private messages sent between users.

PumpUp describes itself as a health and fitness community. Its developed social health tracking application PumpUp supports Android and iOS platforms and claims to have more than 6 million users worldwide. With this app, users can share selfies and health tips, formulate and save custom workout plans, and get advice from fitness trainers and other users. On the other hand, it can also be used to track user activity such as calories burned, exercise time, exercise progress, etc.

All of this data is stored on a core back-end server and hosted on Amazon’s cloud. However, security researcher Oliver Hough found that the server did not set a password, which allows anyone to see who is logged in, who is sending messages in real time, and the content of the message.

According to the contents of PumpUp’s statement, the server is used to act as a messaging agent and is responsible for sending user requests and private messages to other PumpUp application users. The agent uses the little-known MQTT protocol and is often used by developers for communication between IoT devices and mobile applications.

At the same time, this protocol is also a low-bandwidth protocol, which can reduce server costs and data overhead. But because it is also a temporary agreement, it allows anyone to view real-time data streams instead of accessing large, centralized data stores. This means that whenever a user sends a message to another user, the PumpUp application will reveal the user’s profile and session message content.

ZDNet pointed out that the exposed data mainly includes the user’s e-mail address, birth date, gender, and geographic information of the user’s location, as well as the user’s biometrics, exercise and activity goals, user avatars, and whether the user has been blocked or not. The application was rated. In addition, the app also exposed user-submitted health information such as height, weight, caffeine, and alcohol intake, smoking frequency, health problems, medications, and injuries.

 

The exposed data also includes some device data, such as iOS and Android advertising identifiers, the user’s IP address, and the application’s session token, which can be used to access the user’s account without a password.

Users who log in using Facebook accounts also expose their access tokens and put their Facebook accounts at risk.

In some cases, exposure may also include unencrypted user credit card data such as card number, expiration date, and Card Verification Value (CVV).

 

ZDNet said that they spent more than a week to get in touch with PumpUp, but they did not receive any response from PumpUp. The good news is that the server was password protected earlier last week, but it is not clear how long this server has been exposed.

Source, Image: ZDNet

Related coverage

  • Android’s Secret Tracking: Meta & Yandex Abused Localhost for User Data
  • Panerabread data breach, millions of customer info was leaked
  • AgentRun data leak reveals personal sensitive information of customers
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: PumpUp leak

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-73807CVSS 9.8
    The mySCADA myPRO Manager command API does not properly enforce authentication for...
  • CVE-2026-81855CVSS 9.1
    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing...
  • CVE-2026-78225CVSS 9.0
    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller...
  • CVE-2026-61560CVSS 9.8
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version...
  • CVE-2026-73437CVSS 9.6
    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP)...
  • CVE-2026-61559CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version...
  • CVE-2026-91939CVSS 9.8
    Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without...
  • CVE-2026-61568CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to...
  • CVE-2026-66887CVSS 9.6
    The affected products are missing authorization on state-changing CGIs and session checks...
  • CVE-2026-66890CVSS 9.6
    The affected products use hard-coded credentials, which could allow remote access to...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.