Junglewise Threat Intelligence

CVE-2026-9046: Lenovo Legion Zone and App Store insecure permissions in Windows applications

CVE-2026-9046 · Severity: high · CVSS 7 · Published 2026-07-16

Vendors: Lenovo.

Executive brief

Lenovo Legion Zone and the Lenovo App Store are Windows applications used for device management and software distribution. A security flaw in these applications allows a local user on a shared computer to gain unauthorized control over the system if the software was installed on a secondary hard drive partition. This could lead to the execution of malicious software or full system compromise by an attacker with physical or remote access to a standard user account.

Technical details

An insecure inherited permissions vulnerability (CWE-277) exists in Lenovo Legion Zone (versions prior to 2.0.26) and Lenovo App Store (versions prior to 9.0.29) for Windows. The flaw is triggered when the applications are installed on a non-system partition, where default folder permissions may allow low-privileged local users to modify application binaries or configuration files. An attacker with local access can exploit these weak permissions to replace legitimate files with malicious code, leading to arbitrary code execution with the privileges of the application or the user running it. The vulnerability is specific to the Chinese market distribution of these tools. Users are advised to update to the latest versions to remediate the risk.

Affected products

  • Lenovo Legion Zone < 2.0.26
  • Lenovo App Store < 9.0.29

Timeline

  • 2026-07-16: disclosed
  • 2026-07-16: advisory

References

Related threats