What is CVE-2026-16791?
CVE-2026-16791 is a temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI (version 5.5.0 and below). This flaw allows a local low-privileged attacker to overwrite or truncate arbitrary files with program-generated data when OneCLI runs with elevated privileges. Affected users should update OneCLI to the latest version to mitigate the risk.
Azərbaycanca: CVE-2026-16791, Lenovo XClarity Essentials OneCLI-nin Linux versiyasında tapılan müvəqqəti fayl yaratma zəifliyidir. Bu boşluq, proqram yüksək imtiyazlarla işə salındıqda yerli aşağı səlahiyyətli təcavüzkarın ixtiyari faylları proqram tərəfindən yaradılan məlumatlarla üzərinə yazmasına və ya kəsməsinə imkan verir. Təsirə məruz qalan istifadəçilər OneCLI-ni ən son versiyaya yeniləməli və müvəqqəti fayl əməliyyatlarını məhdudlaşdırmalıdır.
Related CVEs
link basis: shared vendor: Lenovo
FAQ2
What can an attacker exploiting CVE-2026-16791 do?
The attacker can overwrite or truncate arbitrary files with program-generated data when the program runs with elevated privileges.
Which versions of Lenovo XClarity Essentials OneCLI are vulnerable to CVE-2026-16791?
Version 5.5.0 and below of the Linux version are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.