Skip to content
Threat Feed
high advisory

Improper Authorization Vulnerability in Lenovo File Manager Android App

A local improper authorization vulnerability in the Lenovo File Manager Android app allows authenticated local users to read or modify protected application files.

CVE search metadata

CVE search record: CVE-2026-18994. Severity: high. CVSS: 7.1. KEV: no. Product: File Manager (Chinese market distribution). Brief: Improper Authorization Vulnerability in Lenovo File Manager Android App. Brief link: https://feed.craftedsignal.io/briefs/2026-09-lenovo-file-manager-vuln/

An improper authorization vulnerability (CVE-2026-18994) has been identified in the Lenovo File Manager Android application. This vulnerability is specific to the version of the application distributed within the Chinese market. It allows a local, authenticated user to bypass existing authorization controls, granting them the ability to read or modify protected files maintained by the application. This could lead to unauthorized data exposure or manipulation of sensitive user data stored within the app's directory. Defenders should note that this is a local attack vector requiring the adversary to have already gained access to the mobile device or have an application running with sufficient permissions to interface with the Lenovo File Manager.

Impact

The vulnerability affects the Lenovo File Manager application distributed in the Chinese market. Successful exploitation allows a local user to gain unauthorized access to protected file resources, potentially resulting in data exfiltration or corruption. The CVSS base score for this vulnerability is 7.1.

Recommendation

Prioritize the identification of Lenovo File Manager installations on mobile devices managed within the organization. Check for updates provided via the official vendor channels for the Chinese market and apply patches immediately. As this is a local privilege escalation vector, audit Android permissions and ensure that only trusted applications are installed on devices that have access to corporate data.


Immediate actions

Inventory all mobile devices to identify the presence of Lenovo File Manager.

IT Operations 48h

Mitigations

Remove or update the application if official patches are released for the identified Chinese market version.

medium_term IT Operations

CVE-2026-18994