CVE-2026-0827: Medium severity Lenovo Lenovo Diagnostics vulnerability
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lenovo Diagnosticsto a version that resolves this vulnerability.Fixed in 5.26.0 - Upgrade
Upgrade
Lenovo Vantage HardwareScanAddin / Lenovo Commercial Vantage HardwareScanAddinto a version that resolves this vulnerability.Fixed in 4.7.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0827?
CVE-2026-0827 has been rated as a medium severity vulnerability.
How do I fix CVE-2026-0827?
To fix CVE-2026-0827, users should ensure they install the latest updates provided by Lenovo for the affected software.
What impact does CVE-2026-0827 have on my system?
CVE-2026-0827 can potentially allow a local authenticated user to perform arbitrary file writes with elevated privileges.
Which software is affected by CVE-2026-0827?
CVE-2026-0827 affects Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage.
Who is vulnerable to CVE-2026-0827?
Local authenticated users on systems with Lenovo Diagnostics and the HardwareScanAddin may be vulnerable to CVE-2026-0827.