CVE-2026-11813
nicheLocal Privilege Escalation via Improper Permissions in Lenovo Filez Client
Lenovo Filez Client contains an improper permissions vulnerability (CWE-276) that could allow a local authenticated user to escalate privileges on the affected machine. The flaw is triggered locally by an authenticated user on a system where the Filez Client is installed, with no user interaction or network access required per the CVSS 4.0 vector (AV:L/PR:L/UI:N). An attacker who successfully exploits it gains highly privileged access on that endpoint, with high impact on confidentiality, integrity, and availability of the local system (VC:H/VI:H/VA:H). Affected parties are users of endpoints running the Lenovo Filez Client, Lenovo's enterprise file collaboration/synchronization client, meaning exposure is concentrated in organizations that have deployed this product. There is no evidence of active exploitation: the issue is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Monitor the Lenovo PSIRT advisory for CVE-2026-11813 and apply the updated Filez Client build as soon as Lenovo publishes affected and fixed version details. In the interim, prioritize shared or multi-user endpoints where local accounts are broadly available, since exploitation requires local authenticated access. Review permissions on Filez Client installation and service components on endpoints for overly permissive ACLs that unprivileged users could leverage.
| Lenovo Filez Client | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.
- Weakness
- CWE-276
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.