{"id":"CVE-2026-63427","title":"An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.","summary":"An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-290"],"vendor":"Lenovo","product":"Software Fix","affected":["software_fix < 7.6.2.10"],"published":"2026-09-10","updated":"2026-09-15","sourceUpdated":"2026-09-15T04:18:09.087","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63427","references":[{"url":"https://support.lenovo.com/us/en/downloads/ds101291-rescue-and-smart-assistant-lmsa","label":"psirt@lenovo.com"},{"url":"https://support.lenovo.com/us/en/product_security/LEN-217409","label":"psirt@lenovo.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-14T00:00:00+00:00"},"epss":0.00194,"epssPercentile":0.08105,"ingestedAt":"2026-09-14T13:32:31.115Z","slug":"CVE-2026-63427","body":"## Overview\n\nAn authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}