Improper Link Following in Lenovo Vantage and Commercial Vantage
CVE-2026-15994

7.3HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
13 August 2026

What is CVE-2026-15994?

An improper link following vulnerability was discovered in Lenovo Vantage and Lenovo Commercial Vantage. This flaw allows local authenticated users to execute arbitrary code with elevated privileges, potentially compromising the integrity of the system. Users are advised to monitor their systems and apply necessary security patches to mitigate this risk.

Affected Version(s)

Commercial Vantage 0 < 20.2026.20.0

Vantage 0 < 10.2606.12

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.