Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo FileZ Android application to version 11.1.0.35 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.filez.com/securityPolicy |
|
Fri, 20 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Certificate Validation in Lenovo FileZ Allows Arbitrary Code Execution |
Thu, 12 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code. | |
| First Time appeared |
Lenovo
Lenovo filez |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:lenovo:filez:*:*:android:*:*:*:*:* cpe:2.3:a:lenovo:filez:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo filez |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-03-12T16:19:05.164Z
Reserved: 2026-02-11T20:29:58.887Z
Link: CVE-2026-2368
Updated: 2026-03-12T15:37:57.035Z
Status : Awaiting Analysis
Published: 2026-03-11T21:16:15.473
Modified: 2026-03-12T21:08:22.643
Link: CVE-2026-2368
No data.
OpenCVE Enrichment
Updated: 2026-03-20T15:37:16Z