CVE Database
/

CVE-2026-6282

Back to search

CVE-2026-6282

Published: May 13, 2026

Modified: May 13, 2026

PUBLISHED

CVSS v3.1

8.1

HIGH

Description

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.

VendorProductVersions

Lenovo

Personal Cloud T2s

affected
0 - < 5.5.6.t2s.3

Lenovo

Personal Cloud T2Pro

affected
0 - < 5.4.8.t2pro.2

Lenovo

Personal Cloud X1s

affected
0 - < 5.4.8.x1s.2

Lenovo

Home Storage Hub T20

affected
0 - < 5.5.8.t20.1

Lenovo

Home Storage Hub X20

affected
0 - < 5.4.4.x20.1

Lenovo

Personal Cloud T1

affected
0 - <= 5.4.0.t1.6

Lenovo

Personal Cloud A1

affected
0 - <= 5.4.2.a1.3

Lenovo

Personal Cloud A1s

affected
0 - <= 5.5.6.a1s

Lenovo

Personal Cloud T2

affected
0 - <= 5.4.5.t2.2

Lenovo

Personal Cloud X1

affected
0 - <= 5.4.7.x1.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now