AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-12036

HIGH · CVSS 7.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage is vulnerable to an improper link following issue, enabling a local authenticated user to delete arbitrary files with elevated privileges. This flaw poses a significant risk as it could lead to unauthorized data manipulation or loss. Organizations using these products should prioritize remediation to mitigate potential exploitation by malicious insiders.

CVE
CVE-2026-12036
Severity
HIGH
CVSS
7.1
EPSS
0.16%

Original NVD Description

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.