Temporary File Creation Flaw in Lenovo XClarity Essentials OneCLI
CVE-2026-16791
1LOW
What is CVE-2026-16791?
The temporary file creation flaw in the Linux version of Lenovo XClarity Essentials OneCLI allows a low-privileged local attacker to exploit the privilege escalation when OneCLI is executed with elevated permissions. This could potentially enable the attacker to overwrite or truncate arbitrary local files, leading to data integrity issues. It’s imperative for users to apply relevant patches and updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
XClarity Essentials OneCLI Linux 0 < 5.6
References
CVSS V4
Score:
1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.