Junglewise Threat Intelligence

CVE-2026-6511: Lenovo Smart Connect improper access control in Windows

CVE-2026-6511 · Severity: medium · CVSS 5.5 · Published 2026-07-16

Vendors: Lenovo.

Executive brief

Lenovo Smart Connect is a software tool used to integrate Lenovo PCs with other devices for file sharing and cross-device functionality. A security flaw in this software could allow a person who already has a basic user account on a computer to view private files belonging to other users on that same machine. This could lead to the unauthorized exposure of sensitive personal or corporate data stored on shared workstations.

Technical details

An improper access control vulnerability (CWE-306) exists in Lenovo Smart Connect for Windows versions prior to 09.0.2.003.000. The flaw stems from insufficient validation of file access permissions within the application's local service or file-handling component. An attacker with local authenticated access to the system can exploit this to bypass standard file system isolation and read files owned by other users. The vulnerability requires local access and valid credentials but no user interaction. Lenovo has released version 09.0.2.003.000 to address this issue.

Affected products

  • Lenovo Smart Connect for Windows before 09.0.2.003.000

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats