๐Ÿ” CVE Alert

CVE-2026-1636

MEDIUM 6.7
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

CWE CWE-427
Vendor lenovo
Product service bridge
Published Apr 15, 2026
Last Updated Apr 16, 2026
Stay Ahead of the Next One

Get instant alerts for lenovo service bridge

Be the first to know when new medium vulnerabilities affecting lenovo service bridge are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Lenovo / Service Bridge
0 < 5.0.2.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.lenovo.com: https://support.lenovo.com/us/en/product_security/LEN-211071

Credits

Lenovo thanks Victor Rodriguez (aka NT3P) for reporting this issue.