An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.
Advisories
No advisories yet.
Fixes
Solution
Update Lenovo FileZ Android application to version 11.1.0.35 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.filez.com/securityPolicy |
|
History
Wed, 11 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code. | |
| First Time appeared |
Lenovo
Lenovo filez |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:lenovo:filez:*:*:android:*:*:*:*:* cpe:2.3:a:lenovo:filez:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo filez |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-03-11T20:21:05.818Z
Reserved: 2026-02-11T20:29:58.887Z
Link: CVE-2026-2368
No data.
Status : Received
Published: 2026-03-11T21:16:15.473
Modified: 2026-03-11T21:16:15.473
Link: CVE-2026-2368
No data.
OpenCVE Enrichment
No data.
Weaknesses