Skip to content
Threat Feed

Vendor

Lenovo

18 briefs RSS
high advisory

Authentication Bypass in Lenovo Software Fix

CVE-2026-63427 is an authentication bypass vulnerability in Lenovo Software Fix that allows a local authenticated user to escalate privileges and execute arbitrary code.

Software Fix vulnerability privilege-escalation
1t 1c
high advisory

Improper Authorization Vulnerability in Lenovo File Manager Android App

A local improper authorization vulnerability in the Lenovo File Manager Android app allows authenticated local users to read or modify protected application files.

File Manager vulnerability android privilege-escalation
1t 1c
high advisory

Privilege Escalation in Lenovo Filez Client

Lenovo Filez Client contains an improper permissions vulnerability (CVE-2026-11813) that allows local authenticated users to escalate privileges.

Filez Client vulnerability privilege-escalation
1t 1c
critical advisory

Critical Vulnerability in Lenovo Health Android Application

A high-severity vulnerability in the Lenovo Health Android application, exclusively distributed in the Chinese market, allows unauthorized access to sensitive user health data.

Lenovo Health Android Application
1c
high advisory

Authentication Bypass in Lenovo System Update

CVE-2026-6387 is an authentication bypass vulnerability in Lenovo System Update (versions prior to 5.08.04.85) that allows a local authenticated user to escalate privileges and execute arbitrary code.

System Update
1t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Dock Manager

Lenovo Dock Manager versions prior to 1.6.5.3 contain a local privilege escalation vulnerability due to an improperly protected key, allowing authenticated local users to gain elevated access.

Dock Manager vulnerability privilege-escalation lenovo
1t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Accessories and Display Manager

Lenovo Accessories and Display Manager for Enterprise for Windows version 1.0.9 and earlier contains a hard-coded cryptographic key vulnerability (CVE-2026-63423) that allows local authenticated users to achieve arbitrary code execution with elevated privileges.

Accessories and Display Manager privilege-escalation windows lenovo cve
1t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Vantage

Lenovo Vantage and Commercial Vantage contain an improper link following vulnerability (CVE-2026-15994) that allows local authenticated users to achieve privilege escalation through file system manipulation.

Vantage +1 vulnerability privilege-escalation lenovo
1t 1c
high advisory

OS Command Injection in Lenovo XClarity Orchestrator

Lenovo XClarity Orchestrator (LXCO) versions prior to 2.2.0 contain an OS command injection vulnerability (CVE-2026-16793) allowing authenticated attackers to execute arbitrary commands with high privileges.

XClarity Orchestrator cve rce injection enterprise-management
1t 1c
high advisory

CVE-2026-9046: Insecure Permissions in Lenovo Legion Zone and App Store Leads to Local Arbitrary Code Execution

CVE-2026-9046 describes an insecure permissions vulnerability in Lenovo's Legion Zone and Lenovo App Store Windows applications, distributed exclusively in the Chinese market, which, when installed on a non-system partition, allows a local low-privileged user to execute arbitrary code, leading to high impact on confidentiality, integrity, and availability.

Legion Zone +1 insecure-permissions local-privilege-escalation windows arbitrary-code-execution
2t 1c
high threat

CVE-2026-13104: Privilege Escalation in Lenovo App Store (Chinese Market)

A high-severity vulnerability, CVE-2026-13104, has been identified in specific versions of the Lenovo App Store, exclusively distributed in the Chinese market, which allows a local authenticated user to execute arbitrary code with elevated privileges, potentially leading to full system compromise.

exploited App Store < 9.0.2930.0514 privilege-escalation local-privilege-escalation application-vulnerability
1t 1c
high advisory

Lenovo App Store Path Traversal Vulnerability (CVE-2026-13103) Leading to Arbitrary Code Execution

A critical path traversal vulnerability, identified as CVE-2026-13103, exists in the Lenovo App Store, enabling a local authenticated user to achieve arbitrary code execution on affected Windows systems within the Chinese market.

Lenovo App Store vulnerability path-traversal rce lenovo
1t 1c
medium threat

Lenovo LegionSpace 1.7.11.2 Unquoted Service Path Vulnerability

A local exploit has been published for Lenovo LegionSpace 1.7.11.2, detailing an Unquoted Service Path vulnerability in the 'DAService', potentially leading to local privilege escalation.

LegionSpace unquoted-service-path privilege-escalation windows
2r 1t
high advisory

CVE-2026-5804 - Motorola Factory Test Improper Authentication Vulnerability

The Motorola Factory Test component (com.motorola.motocit) contains an improper authentication vulnerability, allowing a local attacker to bypass permission checks and access protected device settings by leveraging a writable file descriptor in external storage to open a TCP server.

Factory Test component privilege-escalation android cve-2026-5804
2r 1t 1c
medium advisory

Lenovo Personal Cloud Storage Improper File Path Validation Vulnerability (CVE-2026-6282)

CVE-2026-6282 describes a potential improper file path validation vulnerability in Lenovo Personal Cloud Storage devices, allowing a remote authenticated user to move or access files belonging to other users.

Personal Cloud Storage devices cve path traversal lenovo
2r 1t 1c
high advisory

CVE-2026-6281: Lenovo Personal Cloud Storage Remote Command Execution

CVE-2026-6281 describes a vulnerability in Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

Personal Cloud Storage devices cve-2026-6281 rce command injection lenovo
2r 1t 1c
medium advisory

Suspicious PowerShell Engine ImageLoad

This rule identifies instances where the PowerShell engine is loaded by processes other than powershell.exe, potentially indicating attackers attempting to use PowerShell functionality stealthily by using the underlying System.Management.Automation namespace and bypassing PowerShell security features.

Elastic Defend powershell execution windows
2r 1t
low advisory

Startup or Run Key Registry Modification

Attackers modify registry run keys or startup keys to achieve persistence by referencing a program that executes when a user logs in or the system boots.

Elastic Defend +6 persistence registry runkey
3r 2t