{"id":"CVE-2026-18058","title":"The mobile Smart Connect dashboard UI was subject to manipulation\nby 3rd party apps","summary":"The mobile Smart Connect dashboard UI was subject to manipulation\nby 3rd party apps. When paired with a phishing attack, this manipulation could\nresult in escalated privileges of an attacker within the system.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-862"],"published":"2026-09-02","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:44:20.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18058","references":[{"url":"https://en-us.support.motorola.com/app/answers/detail/a_id/193303","label":"psirt@lenovo.com"}],"tags":["nvd"],"epss":0.0008,"epssPercentile":0.00157,"ingestedAt":"2026-09-09T16:14:05.518Z","slug":"CVE-2026-18058","body":"## Overview\n\nThe mobile Smart Connect dashboard UI was subject to manipulation\nby 3rd party apps. When paired with a phishing attack, this manipulation could\nresult in escalated privileges of an attacker within the system.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}