Junglewise Threat Intelligence

CVE-2026-11813: Lenovo Filez Client privilege escalation via improper permissions

CVE-2026-11813 · Severity: high · CVSS 7.8 · Published 2026-09-10

Vendors: Lenovo.

Executive brief

The Lenovo Filez Client application contains an improper permissions vulnerability that allows authenticated local users to escalate their privileges on the system. An attacker with a user account on a machine running Filez Client could gain elevated access to perform unauthorized administrative actions or access sensitive data, compromising system integrity and data security.

Technical details

A privilege escalation vulnerability exists in Lenovo Filez Client due to improper permissions configuration. The vulnerability is exploitable by a local authenticated user without requiring elevated privileges initially, allowing them to escalate to higher privilege levels through the vulnerable permission mechanism. The attack vector is local and requires an authenticated user account already present on the system. Patches are available: Windows Enterprise Edition should be updated to version 11.5.1.0 or later, and Windows Public Edition should be updated to version 11.7.6.0 or later.

Affected products

  • Lenovo Filez Client Windows versions prior to 11.5.1.0 (Enterprise) and 11.7.6.0 (Public)

Timeline

  • 2026-09-10: disclosed
  • 2026-07-14: patched: Security advisory issued with patch availability

References