ZeroHour

CVE-2026-18994

mass

Local Authorization Flaw in Lenovo File Manager Android App Exposes Protected Files

CVSS 4.0
8.4 high
EPSS
Published
()
Modified
AI analysis

Lenovo has disclosed an improper authorization flaw (CWE-926) in its File Manager Android application, which is distributed exclusively in the Chinese market. The flaw allows a local authenticated user on the device to bypass the application's access controls and read or modify files that the application protects. Successful exploitation has a high confidentiality and integrity impact on data handled by the app (CVSS 4.0 score of 8.4), but there is no impact on other system components, no user interaction required, and no network-based attack vector. Only Chinese-market Lenovo Android devices with this app are affected; the specific affected version ranges are not stated in the available data and should be confirmed in Lenovo's PSIRT advisory. There is currently no public proof-of-concept, no reported exploitation, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Check Lenovo's PSIRT advisory for CVE-2026-18994 for the affected and fixed version ranges, and update the Lenovo File Manager app via Lenovo's Chinese-market app/update channel on any affected devices. Because exploitation requires local access and there is no remote attack vector, overall risk is limited to on-device data handled by the app; no workarounds are published, and no in-the-wild exploitation has been reported.

Affected
Lenovo File Manager Android Application (Chinese-market distribution only)
Estimated exposure
massplausibly millions of users (China-only app across Lenovo's Android installed base; no published install counts) — Lenovo's Chinese-market Android device volumes run into the millions of units annually, so a China-exclusive File Manager app plausibly reaches a seven-figure user base, though exact distribution or install counts are not published.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.

Weakness
CWE-926
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.