Junglewise Threat Intelligence

CVE-2026-10590: Lenovo BIOS missing authentication in SMI handler via WMI

CVE-2026-10590 · Severity: medium · CVSS 4.4 · Published 2026-07-16

Technologies: Lenovo Legion Pro 7 16AFR10H BIOS, Lenovo Legion Pro 5 16ADR10 BIOS, Lenovo LOQ 15ARP10E BIOS, Lenovo Yoga Book 9 14IAH10 BIOS, Lenovo Legion Pro 5 16AFR10 BIOS, Lenovo IdeaPad Pro 5 16IPH11 BIOS, Lenovo V15 G6 ARP BIOS, Lenovo Legion Pro 7 16ADR10H BIOS, Lenovo Legion 7 16AGP11 BIOS, Lenovo IdeaPad Pro 5 16AGP11 BIOS, Lenovo Yoga Pro 7 15IPH11 BIOS. Vendors: Lenovo.

Executive brief

A security vulnerability in the BIOS firmware of various Lenovo laptops could allow a user with administrative privileges to interfere with low-level system operations. By sending specific commands, an attacker could trigger system interrupts that are normally restricted, potentially compromising the integrity of the device's hardware management. This issue requires local access to the machine and high-level permissions to exploit.

Technical details

This vulnerability is classified as a missing authentication flaw within the BIOS WMI (Windows Management Instrumentation) interface. A local attacker with high privileges (Administrator/SYSTEM) can issue specific WMI commands to trigger a System Management Interrupt (SMI) handler without proper authorization checks. SMIs operate in System Management Mode (SMM), a highly privileged execution mode; unauthorized access to these handlers can lead to arbitrary code execution at the firmware level or bypass of hardware-based security protections. Lenovo has released BIOS updates for affected models to address this issue.

Affected products

  • Lenovo Yoga Pro 7 15IPH11 BIOS < TNCN37WW
  • Lenovo IdeaPad Pro 5 16IPH11 BIOS < S4CN62WW
  • Lenovo Legion 7 16AGP11 BIOS <= TPCN27WW
  • Lenovo IdeaPad Pro 5 16AGP11 BIOS <= T8CN19WW
  • Lenovo Legion Pro 5 16ADR10 BIOS <= U5CN07WW
  • Lenovo Lenovo V15 G6 ARP BIOS <= TYCN15WW
  • Lenovo LOQ 15ARP10E BIOS < SUCN18WW
  • Lenovo Yoga Book 9 14IAH10 BIOS <= QEME23WW
  • Lenovo Legion Pro 7 16AFR10H BIOS < SMCN20WW
  • Lenovo Legion Pro 5 16AFR10 BIOS <= RECN14WW
  • Lenovo Legion Pro 7 16ADR10H BIOS < SJCN17WW

Timeline

  • 2026-07-16: advisory: Initial disclosure by Lenovo and NVD publication

References

Related threats