Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update VantageCoreAddin to version 1.1.0.51 or later. VantageCoreAddin is updated automatically.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-223723 |
|
Thu, 13 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Authenticated User Can Delete Arbitrary Files Using Improper Link Following in Lenovo Vantage Addin |
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo vantage |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:lenovo:vantage:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo vantage |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-08-13T16:05:20.251Z
Reserved: 2026-06-11T18:45:15.709Z
Link: CVE-2026-12036
Updated: 2026-08-13T16:05:13.150Z
Status : Received
Published: 2026-08-13T15:19:28.293
Modified: 2026-08-13T16:17:52.660
Link: CVE-2026-12036
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:00:04Z
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')