CVE-2026-16791: Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
Published Aug 4, 2026
·Updated
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Affected Software
1 affected component
Lenovo XClarity Essentials OneCLI<=5.5.0
Event History
Aug 4, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness