CVE-2026-16791: Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
Published Aug 4, 2026
·Updated
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Affected Software
1 affected component
Lenovo XClarity Essentials OneCLI<=5.5.0
Event History
Aug 4, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16791?
The severity of CVE-2026-16791 is low.
2
How do I fix CVE-2026-16791?
To fix CVE-2026-16791, update Lenovo XClarity Essentials OneCLI to version 5.5.1 or later.
3
What systems are affected by CVE-2026-16791?
CVE-2026-16791 affects the Linux version of Lenovo XClarity Essentials OneCLI version 5.5.0 and below.
4
Can CVE-2026-16791 be exploited remotely?
No, CVE-2026-16791 requires local access to exploit the vulnerability.
5
What type of attacks can CVE-2026-16791 facilitate?
CVE-2026-16791 can facilitate local attacks that allow low-privileged users to overwrite or truncate arbitrary local files.