CVE-2026-9046: Lenovo App Store

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

Affected products

  • Lenovo App Store: before 9.0.29 (fixed in 9.0.29)
  • Lenovo Legion Zone: before 2.0.26 (fixed in 2.0.26)

Published 2026-07-16. Last modified 2026-07-16.