Description
A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.
Published: 2026-07-16
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Lenovo App Store Windows Application contains a path traversal flaw (CWE-22) that may allow a locally authenticated user to execute arbitrary code with the privileges of that user. The vulnerability arises when the application processes file paths that can be manipulated to reference directories outside the intended working directory, potentially invoking code from malicious locations.

Affected Systems

The vulnerability affects the Lenovo App Store for Windows, distributed exclusively in the Chinese market. Versions prior to 9.0.2930.0514 are susceptible. The impacted product is the Lenovo App Store Windows Application.

Risk and Exploitability

The CVSS score of 7 indicates medium to high severity, but the EPSS score of <1% (0.00132) indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits have been documented. The attack vector is local and requires an authenticated user to run the Lenovo App Store; execution is limited to the user’s own privileges.

Generated by OpenCVE AI on July 31, 2026 at 01:38 UTC.

Remediation

Vendor Solution

Update Lenovo Store Windows Application to version 9.0.2930.0514 or later.


OpenCVE Recommended Actions

  • Install Lenovo Store Windows Application update 9.0.2930.0514 or later.
  • Configure local account permissions to restrict use of the application to trusted users only, enforcing the principle of least privilege.
  • Implement file integrity monitoring on the app’s installation and data directories to detect unauthorized path traversal attempts.

Generated by OpenCVE AI on July 31, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 31 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in Lenovo App Store Enables Arbitrary Code Execution

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Lenovo App Store Enabling Local Code Execution

Fri, 17 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in Lenovo App Store Enabling Local Code Execution

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.
First Time appeared Lenovo
Lenovo app Store
Weaknesses CWE-22
CPEs cpe:2.3:a:lenovo:app_store:*:*:windows:*:*:*:*:*
Vendors & Products Lenovo
Lenovo app Store
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo App Store
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-07-16T17:45:15.555Z

Reserved: 2026-06-23T19:38:58.369Z

Link: CVE-2026-13103

cve-icon Vulnrichment

Updated: 2026-07-16T17:43:34.276Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:45:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')