CVE-2026-18994
massLocal Authorization Flaw in Lenovo File Manager Android App Exposes Protected Files
Lenovo has disclosed an improper authorization flaw (CWE-926) in its File Manager Android application, which is distributed exclusively in the Chinese market. The flaw allows a local authenticated user on the device to bypass the application's access controls and read or modify files that the application protects. Successful exploitation has a high confidentiality and integrity impact on data handled by the app (CVSS 4.0 score of 8.4), but there is no impact on other system components, no user interaction required, and no network-based attack vector. Only Chinese-market Lenovo Android devices with this app are affected; the specific affected version ranges are not stated in the available data and should be confirmed in Lenovo's PSIRT advisory. There is currently no public proof-of-concept, no reported exploitation, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Check Lenovo's PSIRT advisory for CVE-2026-18994 for the affected and fixed version ranges, and update the Lenovo File Manager app via Lenovo's Chinese-market app/update channel on any affected devices. Because exploitation requires local access and there is no remote attack vector, overall risk is limited to on-device data handled by the app; no workarounds are published, and no in-the-wild exploitation has been reported.
| Lenovo File Manager Android Application (Chinese-market distribution only) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.
- Weakness
- CWE-926
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.