SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18994

HIGH · CVSS 7.1 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Lenovo File Manager Android application, available exclusively in the Chinese market, contains an improper authorization vulnerability that allows local authenticated users to read or modify protected files. This could lead to unauthorized access to sensitive data, posing a significant risk to user privacy and data integrity. Organizations utilizing this application should prioritize remediation efforts to mitigate potential exploitation.

CVE
CVE-2026-18994
Severity
HIGH
CVSS
7.1
EPSS
0.10%
Android

Original NVD Description

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.