CVE-2026-16791 LOW

CVE-2026-16791: Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI

Vendor Lenovo
Product XClarity Essentials OneCLI
Weakness CWE-377
Published August 4, 2026
Last update August 5, 2026

CVSS base score

3.9/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.

Key dates

02Disclosure timeline

August 4, 2026 CVE published
August 5, 2026 Record updated