Improper Link Following in Lenovo Vantage and Commercial Vantage
CVE-2026-15994
7.3HIGH
What is CVE-2026-15994?
An improper link following vulnerability was discovered in Lenovo Vantage and Lenovo Commercial Vantage. This flaw allows local authenticated users to execute arbitrary code with elevated privileges, potentially compromising the integrity of the system. Users are advised to monitor their systems and apply necessary security patches to mitigate this risk.
Affected Version(s)
Commercial Vantage 0 < 20.2026.20.0
Vantage 0 < 10.2606.12