ZeroHour

CVE-2026-11813

niche

Local Privilege Escalation via Improper Permissions in Lenovo Filez Client

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

Lenovo Filez Client contains an improper permissions vulnerability (CWE-276) that could allow a local authenticated user to escalate privileges on the affected machine. The flaw is triggered locally by an authenticated user on a system where the Filez Client is installed, with no user interaction or network access required per the CVSS 4.0 vector (AV:L/PR:L/UI:N). An attacker who successfully exploits it gains highly privileged access on that endpoint, with high impact on confidentiality, integrity, and availability of the local system (VC:H/VI:H/VA:H). Affected parties are users of endpoints running the Lenovo Filez Client, Lenovo's enterprise file collaboration/synchronization client, meaning exposure is concentrated in organizations that have deployed this product. There is no evidence of active exploitation: the issue is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Monitor the Lenovo PSIRT advisory for CVE-2026-11813 and apply the updated Filez Client build as soon as Lenovo publishes affected and fixed version details. In the interim, prioritize shared or multi-user endpoints where local accounts are broadly available, since exploitation requires local authenticated access. Review permissions on Filez Client installation and service components on endpoints for overly permissive ACLs that unprivileged users could leverage.

Affected
Lenovo Filez Client
Estimated exposure
nichelikely tens of thousands of enterprise endpoints at most; no published install counts (treat as an estimate) — Filez Client is Lenovo's enterprise file collaboration client deployed on end-user workstations within organizations that adopt the Filez platform rather than a mass-market consumer application, and no public scan or active-install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

Weakness
CWE-276
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.