CVE-2026-9046CWE-277

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the…

High · published July 16, 2026

CVSS v4.0
7.3
EPSS
0%
Percentile
2.5
In the wild
Unconfirmed
What it is

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

The record
Technical detail
CVSS v4.0
7.3 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00125 · 2.5th percentile
Weakness
CWE-277 · Insecure Inherited Permissions
Published
2026-07-16T16:48Z
EPSS history
Timeline
  • 16 JUL 16:48Z
    A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the…
    cvelistv5