Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo System Update to version 5.08.04.85 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Privilege Escalation via Authentication Bypass in Lenovo System Update |
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo system Update |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:lenovo:system_update:*:*:windows:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo system Update |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-08-13T16:07:44.922Z
Reserved: 2026-04-15T19:22:25.659Z
Link: CVE-2026-6387
Updated: 2026-08-13T16:07:41.761Z
Status : Received
Published: 2026-08-13T15:19:58.590
Modified: 2026-08-13T16:18:56.283
Link: CVE-2026-6387
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:15:05Z