CVE-2026-0421
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-252
- Published
- 2026-01-14
- Last modified
- 2026-03-12
Affected products
- Lenovo ThinkPad L13 Gen 6 BIOS
- Lenovo ThinkPad L13 Gen 6 2 in 1 BIOS
- Lenovo ThinkPad L14 Gen 6 BIOS
- Lenovo ThinkPad L16 Gen 2 BIOS
Weakness type
Related vulnerabilities
- CVE-2026-86749 — snipe-it before 8.7.0 Data Loss via Failed Image Write
- CVE-2026-86739 — Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence
- CVE-2026-86141 — xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a...
- CVE-2026-19534 — undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
- CVE-2026-85649 — (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation...
- CVE-2026-14957 — FIPS mode assertion failure via malicious CERT payload
- CVE-2026-78699 — rename_tenant returns :ok on a failed rename, enabling cross-tenant access in AshPostgres
- CVE-2026-79772 — Nokogiri before 1.19.1 Unchecked Return Value canonicalize