Home

Description

A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.

PUBLISHED Reserved 2025-12-04 | Published 2026-01-14 | Updated 2026-01-14 | Assigner lenovo




HIGH: 7.0CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

MEDIUM: 6.5CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-252: Unchecked Return Value

Product status

Default status
unaffected

Any version before 1.10
affected

Default status
unaffected

Any version before 1.10
affected

Default status
unaffected

Any version before 1.06
affected

Default status
unaffected

Any version before 1.06
affected

References

support.lenovo.com/us/en/product_security/LEN-210688

cve.org (CVE-2026-0421)

nvd.nist.gov (CVE-2026-0421)

Download JSON