Description
During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.
Published: 2026-07-16
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During an internal assessment, Lenovo Smart Connect for Windows was found to allow a local authenticated user to read or otherwise access files belonging to a different user on the same machine. The vulnerability arises from improper access control, permitting data leakage across user boundaries. This flaw corresponds to CWE‑306 and can lead to the disclosure of private information, user credentials, or confidential documents stored on a shared system.

Affected Systems

The issue affects Lenovo Smart Connect for Windows running versions prior to 09.0.2.003.000. All earlier releases are potentially vulnerable until the user applies the vendor patch that introduces correct owner checks for file access. The product is used primarily on Windows desktops and laptops, so any machine with Smart Connect installed and a local user who can create or modify files may be impacted.

Risk and Exploitability

The CVSS base score of 6.8 indicates a medium severity vulnerability. Exploitability is limited to local authenticated users, and the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KeV catalog, implying no known widespread exploitation. Organizations with Smart Connect should treat the flaw as a data‑privacy risk and apply the patch promptly.

Generated by OpenCVE AI on July 31, 2026 at 01:39 UTC.

Remediation

Vendor Solution

Update Lenovo Smart Connect for Windows to version 09.0.2.003.000 or later. Smart Connect will prompt the user to download latest version when launched.


OpenCVE Recommended Actions

  • Update Lenovo Smart Connect for Windows to version 09.0.2.003.000 or later.
  • Disable or remove any shared folders or registry entries that allow cross‑user file access until the patch is installed.
  • Audit file permissions on the system to ensure that files owned by other users are set to read‑only for local users.
  • Configure Windows User Account Control or local group policy to restrict executable privileges if relevant.

Generated by OpenCVE AI on July 31, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Local File Access Across Users in Lenovo Smart Connect for Windows

Wed, 29 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allowing Local Users to Read Other Users' Files in Lenovo Smart Connect

Sat, 25 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allowing Local Users to Read Other Users' Files in Lenovo Smart Connect

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Authenticated User Can Access Files of Other Users in Lenovo Smart Connect for Windows

Fri, 17 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local Authenticated User Can Access Files of Other Users in Lenovo Smart Connect for Windows

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.
First Time appeared Lenovo
Lenovo smart Connect
Weaknesses CWE-306
CPEs cpe:2.3:a:lenovo:smart_connect:*:*:windows:*:*:*:*:*
Vendors & Products Lenovo
Lenovo smart Connect
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Smart Connect
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-07-16T17:59:36.981Z

Reserved: 2026-04-17T13:03:29.141Z

Link: CVE-2026-6511

cve-icon Vulnrichment

Updated: 2026-07-16T17:59:33.173Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:45:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function