Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo Software Fix to version 7.6.2.10 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo software Fix |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:lenovo:software_fix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo software Fix |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-09-10T21:00:13.708Z
Reserved: 2026-07-16T19:22:22.180Z
Link: CVE-2026-63427
No data.
Status : Deferred
Published: 2026-09-10T21:17:28.347
Modified: 2026-09-10T21:34:43.440
Link: CVE-2026-63427
No data.
OpenCVE Enrichment
No data.