Description
An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
Published: 2026-09-10
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via local authentication bypass in Lenovo Software Fix
Action: Immediate Patch
AI Analysis

Impact

A local authenticated user can bypass authentication checks in Lenovo Software Fix and execute arbitrary code with elevated privileges. The flaw is classified under CWE-290, indicating an authentication bypass that undermines proper access control.

Affected Systems

Lenovo Software Fix is impacted. The vendor recommends updating to version 7.6.2.10 or later, which contains the fix for this flaw. No other product or version details are specified in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 8.5, indicating high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring a local authenticated user to exploit the authentication bypass and gain elevated rights.

Generated by OpenCVE AI on September 11, 2026 at 05:11 UTC.

Remediation

Vendor Solution

Update Lenovo Software Fix to version 7.6.2.10 or later.


OpenCVE Recommended Actions

  • Apply Lenovo Software Fix v7.6.2.10 or later to all affected endpoints.
  • Restrict local user accounts from executing the affected component or remove unnecessary administrative rights.
  • If feasible, isolate the component by limiting network traffic to it through firewall or VLAN configuration until the update is applied.

Generated by OpenCVE AI on September 11, 2026 at 05:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Authentication Bypass in Lenovo Software Fix Enables Privilege Escalation

Fri, 11 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Authentication Bypass in Lenovo Software Fix Enables Privilege Escalation

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
First Time appeared Lenovo
Lenovo software Fix
Weaknesses CWE-290
CPEs cpe:2.3:a:lenovo:software_fix:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo software Fix
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Software Fix
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-09-15T03:56:15.216Z

Reserved: 2026-07-16T19:22:22.180Z

Link: CVE-2026-63427

cve-icon Vulnrichment

Updated: 2026-09-11T14:49:11.882Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:28.347

Modified: 2026-09-15T04:18:09.087

Link: CVE-2026-63427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:10Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing