An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application.
Advisories
No advisories yet.
Fixes
Solution
Update Lenovo FileZ Android application to version 11.1.0.35 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.filez.com/securityPolicy |
|
History
Wed, 11 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application. | |
| First Time appeared |
Lenovo
Lenovo filez |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:lenovo:filez:*:*:android:*:*:*:*:* cpe:2.3:a:lenovo:filez:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo filez |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-03-11T20:20:53.662Z
Reserved: 2026-01-16T19:33:39.508Z
Link: CVE-2026-1068
No data.
Status : Received
Published: 2026-03-11T21:16:14.137
Modified: 2026-03-11T21:16:14.137
Link: CVE-2026-1068
No data.
OpenCVE Enrichment
No data.
Weaknesses