Lenovo XClarity Essentials OneCLI <5.5.0 Temp File Overwrite Vulnerability
CVE-2026-16791 Published on August 4, 2026
Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Vulnerability Analysis
CVE-2026-16791 can be exploited with local system access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Products Associated with CVE-2026-16791
Want to know whenever a new CVE is published for Lenovo Xclarity Essentials Onecli? stack.watch will email you.
Affected Versions
Lenovo XClarity Essentials OneCLI:- Before 5.6 is affected.