Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo Software Fix to version 7.5.5.19 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-213829 |
|
Wed, 15 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Authenticated File Write Vulnerability in Lenovo Software Fix |
Wed, 15 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo software Fix |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:lenovo:software_fix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo software Fix |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-04-15T13:05:12.030Z
Reserved: 2026-03-13T14:48:31.899Z
Link: CVE-2026-4135
Updated: 2026-04-15T13:05:05.224Z
Status : Awaiting Analysis
Published: 2026-04-15T13:16:24.660
Modified: 2026-04-17T15:09:46.880
Link: CVE-2026-4135
No data.
OpenCVE Enrichment
Updated: 2026-04-15T14:52:52Z