A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
History

Tue, 04 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.
Title Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI
First Time appeared Lenovo
Lenovo xclarity Essentials Onecli
Weaknesses CWE-377
CPEs cpe:2.3:a:lenovo:xclarity_essentials_onecli:*:*:linux:*:*:*:*:*
Vendors & Products Lenovo
Lenovo xclarity Essentials Onecli
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-08-04T19:47:55.096Z

Reserved: 2026-07-23T18:03:47.226Z

Link: CVE-2026-16791

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:30:12Z