Improper Initialization Vulnerability in ThinkPad BIOS by Lenovo
CVE-2026-0940

8.4HIGH

What is CVE-2026-0940?

An improper initialization vulnerability has been identified in the BIOS of select Lenovo ThinkPads. This issue could potentially allow a local privileged user to modify sensitive data and execute arbitrary code within the system, leading to unauthorized access and possible compromise of device functionality. It is crucial for users to stay informed about this vulnerability to mitigate risks through timely updates and security practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ThinkPad P14s Gen 5 BIOS 0 <= 1.17

ThinkPad P15v Gen 3 BIOS 0 <= 1.28

ThinkPad P16v Gen 1 BIOS 0 <= 1.62

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Krzysztof Okupski of IOActive for reporting this issue.
.