---
id: CVE-2026-0520
title: >-
  A potential vulnerability was reported in the Lenovo FileZ Android application
  that, under certain conditions, could allow a local authenticated user to
  retrieve some sensitive data stored in a log file.
summary: >-
  A potential vulnerability was reported in the Lenovo FileZ Android application
  that, under certain conditions, could allow a local authenticated user to
  retrieve some sensitive data stored in a log file.
severity: low
cvss: 2.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-532
vendor: lenovo
product: filez
affected:
  - filez < 11.1.0.37
patched:
  - filez 11.1.0.37
published: '2026-03-11'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0520'
references:
  - url: 'https://www.filez.com/securityPolicy'
    label: psirt@lenovo.com
tags:
  - nvd
epss: 0.00092
epssPercentile: 0.00502
ingestedAt: '2026-08-20T17:59:04.434Z'
---

## Overview

A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

## Affected

- `filez < 11.1.0.37`

## Remediation

Upgrade past the affected range:

- `filez 11.1.0.37`
