Junglewise Threat Intelligence

CVE-2026-18994: Lenovo File Manager improper authorization on Android

CVE-2026-18994 · Severity: high · CVSS 7.1 · Published 2026-09-10

Vendors: Lenovo.

Executive brief

Lenovo File Manager is a file management application for Android devices sold in China. A flaw allows authenticated local users to read or modify protected files that should be restricted, potentially exposing sensitive data or enabling unauthorized modifications to the device's filesystem.

Technical details

An improper authorization vulnerability exists in Lenovo File Manager for Android that fails to properly enforce file access restrictions. The vulnerability requires local access and an authenticated user context on the affected device. An attacker with these preconditions can read or modify protected files that should be access-controlled, bypassing the application's authorization checks. The vulnerability affects versions distributed in the Chinese market; patch availability has not been confirmed from the available advisory information.

Affected products

  • Lenovo File Manager <UNKNOWN>

Timeline

  • 2026-09-10: disclosed

References