SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-9046

HIGH · CVSS 7 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Legion Zone and Lenovo App Store applications for Windows, specifically those distributed in the Chinese market, are susceptible to an insecure permissions vulnerability that enables local users to execute arbitrary code when installed on a non-system partition. This high-severity flaw poses significant risks for users and organizations utilizing these applications, particularly in environments where untrusted users may have access. Organizations operating in the Chinese market should prioritize remediation efforts to mitigate potential exploitation.

CVE
CVE-2026-9046
Severity
HIGH
CVSS
7
EPSS
0.08%
Windows

Original NVD Description

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.