CVE-2026-63425: Lenovo Dock Manager

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute arbitrary code with elevated privileges.

Affected products

  • Lenovo Dock Manager: before 1.6.5.3 (fixed in 1.6.5.3)

Published 2026-08-13. Last modified 2026-09-10.