Improper Permissions Flaw in Lenovo Filez Client Application
CVE-2026-11813
8.5HIGH
Key Information:
- Vendor
Lenovo
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-11813?
A potential flaw in the Lenovo Filez Client application has been identified, which could allow authenticated local users to gain elevated privileges due to improper permission configurations. This vulnerability poses a risk of unauthorized access to sensitive data and control over application functionalities, making it critical for users to ensure their software is up to date and to follow recommended security practices. Mitigation actions should be prioritized to safeguard against potential exploitation.
Affected Version(s)
FileZ Client 0 < 11.7.1.0
FileZ Enterprise 0 < 11.5.1.0
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue.