CVE-2026-18994: Lenovo File Manager Application

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application.

Affected products

  • Lenovo File Manager Application: before 9.8.1.77 (fixed in 9.8.1.77)

Published 2026-09-10. Last modified 2026-09-11.