Junglewise Threat Intelligence

CVE-2026-6090: Lenovo Smart Connect for Windows authentication bypass

CVE-2026-6090 · Severity: high · CVSS 7 · Published 2026-06-10

Vendors: Lenovo.

Executive brief

Lenovo Smart Connect for Windows, a tool used to integrate Lenovo PCs with mobile devices, contains a security flaw that could allow a user already logged into the computer to bypass authentication. If exploited, this would allow a person with limited access to run unauthorized commands with high-level system privileges. This could lead to a full compromise of the device, including the ability to access sensitive data or install malicious software.

Technical details

An authentication bypass vulnerability (CWE-290) exists in Lenovo Smart Connect for Windows. The flaw allows a local authenticated user with low privileges to bypass security checks, potentially through spoofing, to execute arbitrary code with elevated (SYSTEM-level) privileges. The attack requires local access to the machine but does not require user interaction. Lenovo has acknowledged the issue and users are advised to refer to the official Lenovo security advisory LEN-218281 for remediation steps and patched versions.

Affected products

  • Lenovo Smart Connect for Windows

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats