CVE-2026-16791
Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
CVSS Score
3.9
EPSS Score
0.0%
EPSS Percentile
0th
A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
| CWE | CWE-377 |
| Vendor | lenovo |
| Product | xclarity essentials onecli |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for lenovo xclarity essentials onecli
Be the first to know when new low vulnerabilities affecting lenovo xclarity essentials onecli are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
Lenovo / XClarity Essentials OneCLI
0 < 5.6
References
Credits
Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.