Description
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Published: 2026-08-04
Score: 1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the predictable creation of temporary files in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and earlier. An attacker with local, low‑privileged access can run the program under elevated privileges, causing the created temporary file to be named in a predictable manner. The attacker can then create or link a symlink to a target file before the temporary file is written, leading to overwrite or truncation of arbitrary local files. The weakness belongs to CWE‑377: Insecure Temporary File Creation. The impact manifests as local file corruption or deletion, potentially affecting system or application integrity if critical files are targeted.

Affected Systems

The affected product is Lenovo XClarity Essentials OneCLI version 5.5.0 and earlier, running on Linux operating systems. Users running these versions as sudo or root, or executing OneCLI with elevated privileges, are at risk. The advisory specifies a fix in later releases; therefore only the 5.5.0 release line and older should be considered vulnerable.

Risk and Exploitability

The CVSS score is 1, indicating low severity, but the EPSS score is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires local presence; the attacker must be able to execute OneCLI and gain elevated privileges in the system. Since the flaw permits arbitrary file overwrite, once the prerequisite privileges are met, the exploit is straightforward. Administrators should consider this a low‑likelihood yet potentially damaging local attack.

Generated by OpenCVE AI on August 4, 2026 at 21:29 UTC.

Remediation

Vendor Solution

Update the Linux version of Lenovo XClarity Essentials OneCLI to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433


OpenCVE Recommended Actions

  • Upgrade Lenovo XClarity Essentials OneCLI to a version newer than 5.5.0 as recommended by Lenovo.
  • Restrict local users from running OneCLI with elevated privileges; enforce least‑privilege execution.
  • If a patch is unavailable, modify the temporary file handling so that OneCLI creates files with unique, randomly generated names and secure file permissions, or run the service in a confined environment with limited file system access.

Generated by OpenCVE AI on August 4, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Title Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
First Time appeared Lenovo
Lenovo xclarity Essentials Onecli
Weaknesses CWE-377
CPEs cpe:2.3:a:lenovo:xclarity_essentials_onecli:*:*:linux:*:*:*:*:*
Vendors & Products Lenovo
Lenovo xclarity Essentials Onecli
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Xclarity Essentials Onecli
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-08-04T19:47:55.096Z

Reserved: 2026-07-23T18:03:47.226Z

Link: CVE-2026-16791

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:30:12Z

Weaknesses