Lenovo App Store Local Auth PrivEsc Arbitrary Code Exec
CVE-2026-13104 Published on July 16, 2026
A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Vulnerability Analysis
CVE-2026-13104 is exploitable with local system access. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Execution with Unnecessary Privileges
The software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Products Associated with CVE-2026-13104
Want to know whenever a new CVE is published for Lenovo App Store? stack.watch will email you.
Affected Versions
Lenovo App Store:- Before 9.0.2930.0514 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.