An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
Advisories

No advisories yet.

Fixes

Solution

Update Lenovo Software Fix to version 7.6.2.10 or later.


Workaround

No workaround given by the vendor.

History

Fri, 11 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Authentication Bypass in Lenovo Software Fix Enables Privilege Escalation

Fri, 11 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Authentication Bypass in Lenovo Software Fix Enables Privilege Escalation

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
First Time appeared Lenovo
Lenovo software Fix
Weaknesses CWE-290
CPEs cpe:2.3:a:lenovo:software_fix:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo software Fix
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-09-10T21:00:13.708Z

Reserved: 2026-07-16T19:22:22.180Z

Link: CVE-2026-63427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-10T21:17:28.347

Modified: 2026-09-10T21:34:43.440

Link: CVE-2026-63427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:15:17Z

Weaknesses