Skip to content
Threat Feed

Tag

Insecure-Permissions

3 briefs RSS
high advisory

CVE-2026-9046: Insecure Permissions in Lenovo Legion Zone and App Store Leads to Local Arbitrary Code Execution

CVE-2026-9046 describes an insecure permissions vulnerability in Lenovo's Legion Zone and Lenovo App Store Windows applications, distributed exclusively in the Chinese market, which, when installed on a non-system partition, allows a local low-privileged user to execute arbitrary code, leading to high impact on confidentiality, integrity, and availability.

Legion Zone +1 insecure-permissions local-privilege-escalation windows arbitrary-code-execution
2t 1c
high advisory

Insecure Permission Assignment for Garmin OAuth Token Store

The `garminconnect` Python library versions 0.3.4 and earlier insecurely assigned world-readable file permissions to the `garmin_tokens.json` OAuth token store, allowing local attackers on multi-user systems to steal refresh tokens and gain persistent, unauthorized access to victims' Garmin Connect accounts.

garminconnect insecure-permissions credential-theft local-privilege-escalation vulnerability
4t
critical advisory

Snipe-IT File Upload Vulnerability Leads to Remote Code Execution (CVE-2026-37709)

Snipe-IT versions prior to 8.4.1 are vulnerable to remote code execution due to insecure permissions on file uploads, where an attacker can upload arbitrary files and execute code on the server.

snipe-it remote code execution file upload insecure permissions asset management CVE-2026-37709
2r 1t 1c