Junglewise Threat Intelligence

CVE-2026-8637: Lenovo LanSchool Classic uncontrolled search path vulnerability

CVE-2026-8637 · Severity: high · CVSS 7.8 · Published 2026-06-10

Vendors: Lenovo.

Executive brief

LanSchool Classic is a classroom management software used by educators to monitor and manage student devices. A security vulnerability in the client application could allow a student or other user with a standard account on the computer to gain full administrative control. This could lead to unauthorized access to sensitive data, the ability to bypass school security restrictions, or the installation of malicious software.

Technical details

An uncontrolled search path vulnerability (CWE-427) exists in the Lenovo LanSchool Classic client application. The flaw occurs when the application attempts to load a resource or library without specifying a fully qualified path, allowing it to potentially load a malicious file placed in a high-priority directory by an attacker. A local authenticated user with low privileges can exploit this to execute arbitrary code in the security context of the application, which typically runs with elevated permissions. This results in a local privilege escalation (LPE) to administrative or SYSTEM levels. Lenovo has addressed this in an advisory, and users are encouraged to update to the latest version.

Affected products

  • Lenovo LanSchool Classic client

Timeline

  • 2026-06-10: advisory: Initial disclosure by Lenovo and NVD publication.

References