CyberRota Analysis
AI-GeneratedThe VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage is vulnerable to an improper link following issue, enabling a local authenticated user to delete arbitrary files with elevated privileges. This flaw poses a significant risk as it could lead to unauthorized data manipulation or loss. Organizations using these products should prioritize remediation to mitigate potential exploitation by malicious insiders.
CVE
CVE-2026-12036
Severity
HIGH
CVSS
7.1
EPSS
0.16%
Original NVD Description
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.