Executive brief
XClarity Essentials OneCLI is a systems management tool for Linux used to configure and manage Lenovo servers. A flaw in temporary file handling allows a low-privileged local attacker to overwrite or truncate arbitrary files when the tool runs with elevated privileges, potentially corrupting critical system or application files.
Technical details
This is a temporary file creation vulnerability (insecure tempfile handling) in the Linux version of XClarity Essentials OneCLI 5.5.0 and earlier. The vulnerable component creates temporary files in a manner that allows predictable naming or locations, enabling a local low-privileged attacker to exploit a time-of-check-time-of-use (TOCTOU) race condition. When OneCLI is executed with elevated privileges, an attacker can overwrite or truncate arbitrary local files with program-generated data. The attack requires local access and execution context on the affected system, but does not require authentication. Mitigation involves upgrading to a patched version above 5.5.0.
Affected products
- Lenovo XClarity Essentials OneCLI 5.5.0 and below
Timeline
- 2026-08-04: disclosed