Improper Permissions Flaw in Lenovo Filez Client Application
CVE-2026-11813

8.5HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
10 September 2026

What is CVE-2026-11813?

A potential flaw in the Lenovo Filez Client application has been identified, which could allow authenticated local users to gain elevated privileges due to improper permission configurations. This vulnerability poses a risk of unauthorized access to sensitive data and control over application functionalities, making it critical for users to ensure their software is up to date and to follow recommended security practices. Mitigation actions should be prioritized to safeguard against potential exploitation.

Affected Version(s)

FileZ Client 0 < 11.7.1.0

FileZ Enterprise 0 < 11.5.1.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Wanjie from Huazhong University of Science and Technology for reporting this issue.
.