Description
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Published: 2026-08-04
Score: 1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update the Linux version of Lenovo XClarity Essentials OneCLI to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Title Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
First Time appeared Lenovo
Lenovo xclarity Essentials Onecli
Weaknesses CWE-377
CPEs cpe:2.3:a:lenovo:xclarity_essentials_onecli:*:*:linux:*:*:*:*:*
Vendors & Products Lenovo
Lenovo xclarity Essentials Onecli
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Lenovo Xclarity Essentials Onecli
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-08-04T19:47:55.096Z

Reserved: 2026-07-23T18:03:47.226Z

Link: CVE-2026-16791

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:30:12Z

Weaknesses