Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo FileZ Android application to version 11.1.0.35 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.filez.com/securityPolicy |
|
Fri, 20 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Certificate Validation in Lenovo FileZ Allows Sensitive Data Interception |
Thu, 12 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application. | |
| First Time appeared |
Lenovo
Lenovo filez |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:lenovo:filez:*:*:android:*:*:*:*:* cpe:2.3:a:lenovo:filez:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo filez |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-03-12T16:19:12.229Z
Reserved: 2026-01-16T19:33:39.508Z
Link: CVE-2026-1068
Updated: 2026-03-12T15:35:54.256Z
Status : Awaiting Analysis
Published: 2026-03-11T21:16:14.137
Modified: 2026-03-12T21:08:22.643
Link: CVE-2026-1068
No data.
OpenCVE Enrichment
Updated: 2026-03-20T15:37:17Z