A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.
Metrics
Affected Vendors & Products
References
History
Wed, 13 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper File Path Validation in Lenovo Personal Cloud Allows User File Access Hijacking |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device. | |
| First Time appeared |
Lenovo
Lenovo home Storage Hub T20 Lenovo home Storage Hub X20 Lenovo personal Cloud A1 Lenovo personal Cloud A1s Lenovo personal Cloud T1 Lenovo personal Cloud T2 Lenovo personal Cloud T2pro Lenovo personal Cloud T2s Lenovo personal Cloud X1 Lenovo personal Cloud X1s |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:lenovo:home_storage_hub_t20:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:home_storage_hub_x20:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_a1:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_a1s:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_t1:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_t2:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_t2pro:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_t2s:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_x1:*:*:*:*:*:*:*:* cpe:2.3:a:lenovo:personal_cloud_x1s:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo home Storage Hub T20 Lenovo home Storage Hub X20 Lenovo personal Cloud A1 Lenovo personal Cloud A1s Lenovo personal Cloud T1 Lenovo personal Cloud T2 Lenovo personal Cloud T2pro Lenovo personal Cloud T2s Lenovo personal Cloud X1 Lenovo personal Cloud X1s |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published: 2026-05-13T14:15:15.311Z
Updated: 2026-05-13T14:15:15.311Z
Reserved: 2026-04-14T14:42:10.875Z
Link: CVE-2026-6282
No data.
Status : Awaiting Analysis
Published: 2026-05-13T16:17:01.960
Modified: 2026-05-13T16:27:11.127
Link: CVE-2026-6282
No data.