CVE-2026-6090: High severity Lenovo Lenovo Smart Connect for Windows vulnerability
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lenovo Smart Connect for Windowsto a version that resolves this vulnerability.Fixed in 09.0.2.003.000 - Operational
Launch Lenovo Smart Connect; when prompted, download and install the latest version (09.0.2.003.000 or later).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6090?
CVE-2026-6090 has a severity rating of high, with a score of 7.
How do I fix CVE-2026-6090?
To fix CVE-2026-6090, update Lenovo Smart Connect for Windows to version 09.0.2.003.000 or later.
What type of vulnerability is CVE-2026-6090?
CVE-2026-6090 is a potential authentication bypass vulnerability that could allow local authenticated users to execute arbitrary code.
Who is affected by CVE-2026-6090?
CVE-2026-6090 affects users of Lenovo Smart Connect for Windows.
When was CVE-2026-6090 published?
CVE-2026-6090 was published on June 10, 2026.