CVE-2026-9046 Details
Description
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.
A vulnerability exists in the Lenovo Legion Zone and Lenovo App Store Windows applications, specifically those distributed in the Chinese market. This vulnerability arises from potentially insecure permission settings that, when the applications are installed on a non-system partition, could enable a local user to execute arbitrary code.
Users are advised to update the Lenovo Legion Zone application to version 2.0.26 or later and the Lenovo App Store to version 9.0.29 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2026CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://iknow.lenovo.com.cn/detail/441420 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-277 | Insecure Inherited Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lenovo Legion Zone | All versions |
CPE
Remediation
| |
| Lenovo App Store | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | CVE Modified | CISA-ADP |
| Jul 16, 2026 | New CVE Received | [email protected] |
Volerion