CVE-2026-9046: Lenovo App Store
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.
Affected products
- Lenovo App Store: before 9.0.29 (fixed in 9.0.29)
- Lenovo Legion Zone: before 2.0.26 (fixed in 2.0.26)
Published 2026-07-16. Last modified 2026-07-16.