Description
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.
Published: 2026-07-16
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Lenovo’s App Store and Legion Zone for Windows arises from insecure permissions enforcement when the applications are installed on a non‑system partition. This flaw permits a local user to execute arbitrary code within the context of that user. The capability to run arbitrary code risks compromising system and availability through malicious actions performed by the user.

Affected Systems

Lenovo App Store on Windows, versions earlier than 9.0.29, and Lenovo Legion Zone on Windows, earlier than 2.0.26, were distributed exclusively in the Chinese market. The issue applies when either application is installed on a non‑system partition, exposing directories to write access that can be abused by the local user.

Risk and Exploitability

The CVSS score of 7.3 signals high severity, while an EPSS score of less than 1% indicates a very low likelihood of observed exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks require local access to a machine with the affected applications, and the insecure permissions must allow the user to create or modify files used by the application. Based on the description, it is inferred that the flaw lets a local user write to application user’s privileges.

Generated by OpenCVE AI on July 31, 2026 at 01:38 UTC.

Remediation

Vendor Solution

Update Lenovo Legion Zone to version 2.0.26 or later.


OpenCVE Recommended Actions

  • Update Lenovo App Store to version 9.0.29 or later.
  • Update Lenovo Legion Zone to version 2.0.26 or later.
  • If updates cannot be applied immediately, relocate the applications to a write permissions so that only administrators can modify them.

Generated by OpenCVE AI on July 31, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 31 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Insecure Permissions Leading to Local Arbitrary Code Execution in Lenovo Legion Zone and App Store Windows Applications

Tue, 28 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Insecure Permissions Allow Local Arbitrary Code Execution in Lenovo Applications

Sat, 25 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Insecure Permissions Allow Local Arbitrary Code Execution in Lenovo Applications

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Insecure Permissions Allow Local Arbitrary Code Execution in Lenovo App Store and Legion Zone

Mon, 20 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Insecure Permissions Allow Local Arbitrary Code Execution in Lenovo App Store and Legion Zone

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.
First Time appeared Lenovo
Lenovo app Store
Lenovo legion Zone
Weaknesses CWE-277
CPEs cpe:2.3:a:lenovo:app_store:*:*:windows:*:*:*:*:*
cpe:2.3:a:lenovo:legion_zone:*:*:windows:*:*:*:*:*
Vendors & Products Lenovo
Lenovo app Store
Lenovo legion Zone
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo App Store Legion Zone
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-07-16T17:51:28.237Z

Reserved: 2026-05-19T19:01:33.092Z

Link: CVE-2026-9046

cve-icon Vulnrichment

Updated: 2026-07-16T17:51:24.803Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:45:06Z

Weaknesses
  • CWE-277

    Insecure Inherited Permissions