Improper Authorization Vulnerability in Lenovo File Manager Android App
CVE-2026-18994

8.4HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
10 September 2026

What is CVE-2026-18994?

A potential improper authorization vulnerability exists in the Lenovo File Manager Android Application, exclusively available in the Chinese market. This flaw could enable a local authenticated user to gain unauthorized access, allowing them to read or modify protected files within the application. The implications of this vulnerability highlight significant security concerns related to user data integrity and privacy.

Affected Version(s)

File Manager Application Android 0 < 9.8.1.77

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.