Junglewise Threat Intelligence

CVE-2026-6282: Lenovo Personal Cloud Storage path traversal in file management

CVE-2026-6282 · Severity: high · CVSS 8.1 · Published 2026-05-13

Vendors: Lenovo.

Executive brief

A security vulnerability has been identified in several Lenovo Personal Cloud Storage devices, which are used by consumers to store and manage personal files remotely. An attacker with a standard user account on the device could exploit this flaw to access, view, or move files belonging to other users. This could lead to the unauthorized exposure or loss of private data stored on the shared storage system.

Technical details

An improper file path validation vulnerability (CWE-22) exists in the firmware of several Lenovo Personal Cloud Storage models. The flaw allows a remote authenticated attacker to bypass directory restrictions by providing manipulated file paths. By exploiting this, an attacker can perform unauthorized file operations, such as reading or moving data belonging to other user accounts on the same physical device. The vulnerability is particularly significant as several of the affected models (T1, A1, X1, T2, A1s) have reached End of Life (EOL) status, and Lenovo has indicated that security firmware updates for these specific models have been discontinued.

Affected products

  • Lenovo Personal Cloud Storage T1 (L-SSC201-*)
  • Lenovo Personal Cloud Storage A1 (L-SSC101/L-SSC121)
  • Lenovo Personal Cloud Storage X1 (L-SSC501-*)
  • Lenovo Personal Cloud Storage T2 (L-SSC202-*)
  • Lenovo Personal Cloud Storage A1s (L-SSC103-*)

Timeline

  • 2026-04-20: other: Lenovo issues EOL notice for affected models
  • 2026-05-13: advisory: Initial disclosure by Lenovo and NVD publication

References

Related threats