CVE-2026-9046
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-277
- Published
- 2026-07-16
- Last modified
- 2026-07-16
Affected products
- Lenovo Legion Zone
- Lenovo App Store
Weakness type
Related vulnerabilities
- CVE-2026-7891 — The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure...
- CVE-2025-32092 — Insecure inherited permissions for some Intel(R) Graphics Software before version 25.30.1702.0...
- CVE-2025-65111 — SpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
- CVE-2025-64185 — Open OnDemand RPM packages create world writable locations
- CVE-2025-24327 — Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before...
- CVE-2025-11554 — Portabilis i-Educar User Type AccessLevelController.php insecure inherited permissions
- CVE-2025-58437 — Coder's privilege escalation vulnerability could lead to a cross workspace compromise
- CVE-2025-9039 — Information Disclosure in Amazon ECS Container Agent