CVE-2026-16791
Received Received - Intake

Temporary File Creation Flaw in Lenovo XClarity Essentials OneCLI

Vulnerability report for CVE-2026-16791, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Lenovo Group Ltd.

Description

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-05
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lenovo xclarity_essentials_onecli to 5.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-377 Creating and using insecure temporary files can leave application and system data vulnerable to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a temporary file creation issue in Lenovo XClarity Essentials OneCLI 5.5.0 and earlier versions for Linux. A local low-privileged attacker could exploit it to overwrite or truncate arbitrary local files with data generated by the program when OneCLI runs with elevated privileges.

Detection Guidance

This vulnerability involves temporary file creation in Lenovo XClarity Essentials OneCLI 5.5.0 and below. Detection requires checking for the presence of OneCLI versions 5.5.0 or earlier on Linux systems. Inspect installed packages and version numbers using system package managers like rpm, dpkg, or yum.

Impact Analysis

If exploited, this vulnerability could allow an attacker to modify or delete important system files, potentially disrupting services or causing system instability. It requires local access and low privileges but can escalate impact when OneCLI runs with higher privileges.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves local file manipulation on a system where OneCLI is executed with elevated privileges. GDPR and HIPAA focus on data protection and privacy, while this issue relates to file integrity and availability on a local system.

Mitigation Strategies

Upgrade Lenovo XClarity Essentials OneCLI to the latest version above 5.5.0. Remove or restrict execution permissions for older versions if upgrading is not immediately possible. Monitor for unauthorized file modifications or unusual temporary file activity in system directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16791. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart