Junglewise Threat Intelligence

CVE-2026-16791: Lenovo XClarity Essentials OneCLI temporary file overwrite

CVE-2026-16791 · Severity: low · CVSS 3.9 · Published 2026-08-04

Vendors: Lenovo.

Executive brief

XClarity Essentials OneCLI is a systems management tool for Linux used to configure and manage Lenovo servers. A flaw in temporary file handling allows a low-privileged local attacker to overwrite or truncate arbitrary files when the tool runs with elevated privileges, potentially corrupting critical system or application files.

Technical details

This is a temporary file creation vulnerability (insecure tempfile handling) in the Linux version of XClarity Essentials OneCLI 5.5.0 and earlier. The vulnerable component creates temporary files in a manner that allows predictable naming or locations, enabling a local low-privileged attacker to exploit a time-of-check-time-of-use (TOCTOU) race condition. When OneCLI is executed with elevated privileges, an attacker can overwrite or truncate arbitrary local files with program-generated data. The attack requires local access and execution context on the affected system, but does not require authentication. Mitigation involves upgrading to a patched version above 5.5.0.

Affected products

  • Lenovo XClarity Essentials OneCLI 5.5.0 and below

Timeline

  • 2026-08-04: disclosed

References