Description
A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The Lenovo FileZ a local authenticated user to elevate privileges. This vulnerability allows an attacker to gain higher rights within the local environment, threatening confidentiality, integrity, and availability. The weakness is classified as CWE-276.

Affected Systems

Lenovo FileZ Client and Lenovo FileZ Enterprise are affected. No specific version constraints are provided; therefore, any release may be vulnerable until the vendor releases an update. Administrators should verify the installed versions against the vendor's recommended updates.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability. The EPSS score is not available, leaving the likelihood of real-world exploitation uncertain. The flaw is not listed in the CISA KEV catalog. Local authenticated users can exploit it without additional conditions; the attack path is straightforward, requiring only local access.

Generated by OpenCVE AI on September 11, 2026 at 04:38 UTC.

Remediation

Vendor Solution

Update Filez Windows Application Enterprise version to 11.5.1.0 or later.


OpenCVE Recommended Actions

  • Upgrade Lenovo FileZ Windows Application Enterprise to version 11.5.1.0 or later.
  • Upgrade Lenovo FileZ Windows Application to version 11.7.1.0 or later.
  • Apply the principle of least privilege by limiting local user permissions until a patch is applied.

Generated by OpenCVE AI on September 11, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Authenticated User Privilege Escalation in Lenovo FileZ Client

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.
First Time appeared Lenovo
Lenovo filez Client
Lenovo filez Enterprise
Weaknesses CWE-276
CPEs cpe:2.3:a:lenovo:filez_client:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:filez_enterprise:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo filez Client
Lenovo filez Enterprise
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Filez Client Filez Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-09-11T14:46:47.045Z

Reserved: 2026-06-09T15:53:47.545Z

Link: CVE-2026-11813

cve-icon Vulnrichment

Updated: 2026-09-11T14:46:43.078Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:18.357

Modified: 2026-09-11T15:16:58.600

Link: CVE-2026-11813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:10Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions