CVE-2026-63427 Details
Description
An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
An authentication bypass vulnerability has been identified in Lenovo Software Fix (Rescue and Smart Assistant) versions prior to 7.6.2.10. This vulnerability could enable a local authenticated user to execute arbitrary code with elevated privileges.
Users are advised to update Lenovo Software Fix to version 7.6.2.10 or later. Instructions for downloading the update are available on the Lenovo Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 10, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.lenovo.com/us/en/downloads/ds101291-rescue-and-smart-assistant-lmsa | [email protected] | ProductVendor |
| https://support.lenovo.com/us/en/product_security/LEN-217409 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lenovo Software Fix | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 10, 2026 | New CVE Received | [email protected] |
Volerion