CVE-2026-1715: Input Validation
Published Mar 11, 2026
·Updated
An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.
Affected Software
3 affected components
Lenovo Lenovo Vantage
Lenovo Lenovo Baiying
Lenovo Vantage<1.0.8.15
Remediation
Information
Update Vantage DeviceSettingsSystemAddin to version 1.0.8.15 or later.
DeviceSettingsSystemAddin is automatically updated by Lenovo Vantage and Baiying.
Event History
Mar 11, 2026
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1715?
CVE-2026-1715 is considered a high severity vulnerability due to the potential for local authenticated users to gain elevated privileges.
2
How do I fix CVE-2026-1715?
To fix CVE-2026-1715, update to the latest version of Lenovo Vantage or Lenovo Baiying as provided by Lenovo.
3
Who is affected by CVE-2026-1715?
CVE-2026-1715 affects users of Lenovo Vantage and Lenovo Baiying products.
4
What type of vulnerability is CVE-2026-1715?
CVE-2026-1715 is an input validation vulnerability that allows for modification of registry keys.
5
Can CVE-2026-1715 be exploited remotely?
No, CVE-2026-1715 can only be exploited by local authenticated users.