Lenovo Filez Client: Improper Permissions Escalation via Limited Auth User
CVE-2026-11813 Published on September 10, 2026
A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.
Vulnerability Analysis
CVE-2026-11813 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
Products Associated with CVE-2026-11813
stack.watch emails you whenever new vulnerabilities are published in Lenovo Filez Client or Lenovo Filez Enterprise. Just hit a watch button to start following.
Affected Versions
Lenovo FileZ Client:- Before 11.7.1.0 is affected.
- Before 11.5.1.0 is affected.