A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Advisories
No advisories yet.
Fixes
Solution
Update the Linux version of Lenovo XClarity Essentials OneCLI to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/ht116433 |
|
History
Tue, 04 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges. | |
| Title | Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI | |
| First Time appeared |
Lenovo
Lenovo xclarity Essentials Onecli |
|
| Weaknesses | CWE-377 | |
| CPEs | cpe:2.3:a:lenovo:xclarity_essentials_onecli:*:*:linux:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo xclarity Essentials Onecli |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-08-04T19:47:55.096Z
Reserved: 2026-07-23T18:03:47.226Z
Link: CVE-2026-16791
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T21:30:12Z
Weaknesses