No advisories yet.
Solution
Update Lenovo Smart Connect for Windows to version 09.0.2.003.000 or later. Smart Connect will prompt the user to download latest version when launched.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/product_security/LEN-218281 |
|
Wed, 10 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass Allowing Local Privilege Escalation |
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| First Time appeared |
Lenovo
Lenovo smart Connect |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:lenovo:smart_connect:*:*:windows:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo smart Connect |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-06-10T16:06:36.704Z
Reserved: 2026-04-10T15:59:03.867Z
Link: CVE-2026-6090
Updated: 2026-06-10T16:06:33.890Z
Status : Awaiting Analysis
Published: 2026-06-10T15:16:42.513
Modified: 2026-06-10T19:43:28.857
Link: CVE-2026-6090
No data.
OpenCVE Enrichment
Updated: 2026-06-10T16:30:26Z