Skip to content
LenovoCVE-2026-63426

Lenovo Dock Manager: arbitrary file write

Medium6.9CVE-2026-63426 · Published Aug 13, 2026 · updated Sep 10, 2026

During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.

Lenovo advisory

Affected versions

PackageAffectedFixed in
Dock Manager
Product
< 1.6.5.31.6.5.3
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-59

More Lenovo advisories

All Lenovo
Advisory
Lenovo System Update: authentication bypass
High7.3Aug 13
Lenovo Accessories and Display Manager: code execution
High8.5Aug 13
Lenovo Dock Manager: privilege escalation
High7.0Aug 13
Lenovo Dock Manager: insecure permissions
High8.5Aug 13
Lenovo Vantage: code execution
High7.3Aug 13
Lenovo E14 Gen 6 Laptops ELAN TrackPoi: out-of-bounds write
Medium5.7Aug 13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.