Junglewise Threat Intelligence

CVE-2026-13103: Lenovo App Store path traversal code execution

CVE-2026-13103 · Severity: high · CVSS 7.3 · Published 2026-07-16

Vendors: Lenovo.

Executive brief

A security vulnerability has been identified in the Lenovo App Store, a software distribution platform used on Lenovo devices in the Chinese market. An attacker with existing access to a device could exploit this flaw to run unauthorized programs or commands. This could lead to a full system compromise, allowing the attacker to view sensitive data or disrupt operations.

Technical details

A path traversal vulnerability (CWE-22) exists in the Lenovo App Store (distributed in China) for Windows. The flaw allows a local authenticated user to bypass directory restrictions, potentially leading to arbitrary code execution. The attack requires local access to the machine and some level of user interaction. The vulnerability is addressed in version 9.0.2930.0514 and later. The CVSS 3.1 score of 7.3 reflects high impact to confidentiality, integrity, and availability, though it is limited by the requirement for local access and user interaction.

Affected products

  • Lenovo App Store < 9.0.2930.0514

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats