Home

Description

A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

PUBLISHED Reserved 2025-12-16 | Published 2026-03-11 | Updated 2026-03-12 | Assigner lenovo




LOW: 2.4CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

LOW: 2.8CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Problem types

CWE-532: Insertion of Sensitive Information into Log File

Product status

Default status
unaffected

Any version before 11.1.0.37
affected

Credits

Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue. finder

References

www.filez.com/securityPolicy

cve.org (CVE-2026-0520)

nvd.nist.gov (CVE-2026-0520)

Download JSON