AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15994

HIGH · CVSS 7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Lenovo Vantage and Lenovo Commercial Vantage contain an improper link following vulnerability that enables local authenticated users to execute code with elevated privileges. This flaw poses a significant risk as it could allow attackers to gain unauthorized access to sensitive system functions. Organizations using these applications should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-15994
Severity
HIGH
CVSS
7
EPSS
0.16%

Original NVD Description

During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.