CVE-2026-0940
Received
Received - Intake
Improper Initialization in ThinkPad BIOS Allows Local Code Execution
Publication date: 2026-03-11
Last updated on: 2026-03-11
Assigner: Lenovo Group Ltd.
Description
Description
A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lenovo | thinkpad_bios | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-665 | The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used. |