Home

Description

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

PUBLISHED Reserved 2026-01-09 | Published 2026-04-15 | Updated 2026-04-15 | Assigner lenovo




MEDIUM: 6.9CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Problem types

CWE-59: Improper Link Resolution Before File Access ('Link Following')

Product status

Default status
unaffected

Any version before 5.26.0
affected

Default status
unaffected

Any version before 4.7.1.4
affected

Credits

Lenovo thanks Anas Hadane for subsequently reporting this vulnerability. finder

References

support.lenovo.com/us/en/product_security/LEN-210693

cve.org (CVE-2026-0827)

nvd.nist.gov (CVE-2026-0827)

Download JSON