Description
A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Published: 2026-07-16
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local authenticated user may run arbitrary code with higher privileges via the Lenovo App Store. The weakness, identified as CWE-250, allows an attacker to exploit the application to elevate privileges and potentially gain full control of the affected system. This impact allows any user who can log into the local machine with App Store access to bypass security boundaries and execute malicious instructions.

Affected Systems

Lenovo App Store for Windows, distributed exclusively in the Chinese market. The vulnerability applies to all versions prior to 9.0.2930.0514; the exact version list is not enumerated in the data but the fix is provided for version 9.0.2930.0514 or newer.

Risk and Exploitability

The CVSS score of 7.0 indicates a high severity. The EPSS score is reported as <1%, suggesting that exploitation is currently rare but not impossible. The vulnerability is not listed in the CISA KEV catalog, yet it remains significant due to the local execution requirement and the ability to achieve arbitrary code execution with elevated rights. An attacker would need local authentication to the target machine and then run the Lenovo App Store to trigger the flaw.

Generated by OpenCVE AI on July 31, 2026 at 01:38 UTC.

Remediation

Vendor Solution

Update Lenovo Store Windows Application to version 9.0.2930.0514 or later.


OpenCVE Recommended Actions

  • Update Lenovo Store Windows Application to version 9.0.2930.0514 or later.
  • Restrict local authentication for the Lenovo App Store to users who require it, removing unnecessary privileged accounts.
  • Monitor the system for unexpected privileged processes launched by the Lenovo App Store after the update.
  • If the App Store is not needed, consider disabling or uninstalling it to reduce attack surface.

Generated by OpenCVE AI on July 31, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 31 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Lenovo App Store

Wed, 29 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Lenovo App Store Local Privilege Escalation

Sat, 25 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Lenovo App Store Local Privilege Escalation

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Lenovo App Store

Fri, 17 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Lenovo App Store

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.
First Time appeared Lenovo
Lenovo app Store
Weaknesses CWE-250
CPEs cpe:2.3:a:lenovo:app_store:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo app Store
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo App Store
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-07-16T17:38:29.523Z

Reserved: 2026-06-23T19:38:58.998Z

Link: CVE-2026-13104

cve-icon Vulnrichment

Updated: 2026-07-16T17:38:20.652Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:45:06Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges