During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
Advisories
No advisories yet.
Fixes
Solution
Update Lenovo Diagnostics to version 5.26.0 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-210693 |
|
History
Wed, 15 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Arbitrary File Write in Lenovo Diagnostics and Vantage |
Wed, 15 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo diagnostics Lenovo vantage |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:lenovo:diagnostics:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo diagnostics Lenovo vantage |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-04-15T12:27:45.354Z
Reserved: 2026-01-09T19:19:57.946Z
Link: CVE-2026-0827
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-04-15T13:38:28Z
Weaknesses