Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
LenovoCVE-2026-93832

Lenovo Setup App: missing authorization

Medium4.8CVE-2026-93832 · Published Oct 1, 2026 · updated Oct 2, 2026

A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.

Lenovo advisory

Affected versions

PackageAffectedFixed in
Setup App
Product
< 2026-01-012026-01-01
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Lenovo advisories

All Lenovo
Advisory
Lenovo Health Application: hard-coded credentials
Critical9.3Sep 10
Lenovo Software Fix: authentication bypass
High8.5Sep 10
Lenovo File Manager Application: improper authorization
High8.4Sep 10
Lenovo Tianxi AI Agent PC Application: command injection
High8.4Sep 10
Lenovo Filez Client application: insecure permissions
High8.5Sep 10
Lenovo Smart Connect Application: missing authorization
High7.3Sep 2