CVE-2026-10590
Last modified
CVE-2026-10590 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler..
Description
A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Yoga Pro 7 15IPH11 BIOS | < TNCN37WW |
| Lenovo | IdeaPad Pro 5 16IPH11 BIOS | < S4CN62WW |
| Lenovo | Legion 7 16AGP11 BIOS | <= TPCN27WW |
| Lenovo | IdeaPad Pro 5 16AGP11 BIOS | <= T8CN19WW |
| Lenovo | Legion Pro 5 16ADR10 BIOS | <= U5CN07WW |
| Lenovo | Lenovo V15 G6 ARP BIOS | <= TYCN15WW |
| Lenovo | LOQ 15ARP10E BIOS | < SUCN18WW |
| Lenovo | Yoga Book 9 14IAH10 BIOS | <= QEME23WW |
| Lenovo | Legion Pro 7 16AFR10H BIOS | < SMCN20WW |
| Lenovo | Legion Pro 5 16AFR10 BIOS | <= RECN14WW |
| Lenovo | Legion Pro 7 16ADR10H BIOS | < SJCN17WW |
| Lenovo | Lenovo V15 G4 AMN BIOS | < L1CN72WW |
| Lenovo | ThinkBook Plus G6 Rollable BIOS | <= QWCN34WW |
| Lenovo | Legion 5 15IAX10 BIOS | <= S2CN15WW |
| Lenovo | Legion 5 15AKP10 BIOS | <= RYCN22WW |
| Lenovo | Legion 5 15IRX10 BIOS | <= QNCN28WW |
| Lenovo | Legion Pro 5 16IRX10 BIOS | <= S9CN13WW |
| Lenovo | ThinkBook 16p G6 ADR BIOS | < R7CN26WW |
| Lenovo | Legion Pro 5 16ADR10 BIOS | <= RLCN21WW |
| Lenovo | Legion 5 15AHP10 BIOS | < RGCN35WW |
| Lenovo | Legion Pro 7 16IRX9H BIOS | <= N2CN26WW |
| Lenovo | Legion 9 16IRX9 BIOS | <= NXCN20WW |
| Lenovo | IdeaPad Slim 3 16IRU9 BIOS | < P2CN27WW |
| Lenovo | Legion Pro 5 16IRX9 BIOS | < N0CN35WW |
| Lenovo | IdeaPad Pro 5 16IMH9 BIOS | <= MECN68WW |
| Lenovo | Legion Pro 7 16ARX8H BIOS | <= LPCN45WW |
| Lenovo | ThinkBook Plus G4 IRU BIOS | <= LUCN47WW |
| Lenovo | Legion Slim 5 14APH8 BIOS | <= MACN33WW |
| Lenovo | ThinkBook Plus G5 Tab&ThinkBook Plus G5 Station BIOS | <= P8CN42WW |
| Lenovo | Legion Pro 7 16ARX8H BIOS | <= LPCN59WW |
| Lenovo | Lenovo V15 G4 IAH BIOS | < MCCN39WW |
| Lenovo | Lenovo V15 G5 IRL BIOS | < PMCN38WW |
| Lenovo | Yoga Pro 9 14IRP8 BIOS | <= MBCN33WW |
| Lenovo | IdeaPad Slim 3 16IRH8 BIOS | < LTCN44WW |
| Lenovo | IdeaPad Pro 5 16IRH8 BIOS | <= KZCN46WW |
| Lenovo | IdeaPad Slim 3 15AMN8 BIOS | < L1CN51WW |
| Lenovo | Yoga 9 14IRP8 BIOS | < L4CN31WW |
| Lenovo | Legion Pro 5 16ARX8 BIOS | <= LPCN59WW |
| Lenovo | Lenovo S14 G3 IAP BIOS | <= JKCN49WW |
| Lenovo | IdeaPad 5 15ABA7 BIOS | < KACN29WW |
| Lenovo | ThinkBook 16p G5 IRX BIOS | < P5CN31WW |
| Lenovo | Lenovo V15 G2 IJL Laptop BIOS | < HTCN49WW |
| Lenovo | Yoga Pro 9 16IMH9 BIOS | <= NKCN30WW |
| Lenovo | ThinkBook 16p G6 IAX BIOS | < R2CN57WW |
| Lenovo | Legion 7 16IAX10 BIOS | <= RXCN18WW |
| Lenovo | Legion Pro 5 16IAX10 BIOS | <= Q6CN26WW |
| Lenovo | Legion Pro 7 16IAX10H BIOS | <= Q7CN31WW |
| Lenovo | IdeaPad Slim 3 16IRH10R BIOS | <= QDCN23WW |
| Lenovo | Legion 5 15IRX9 BIOS | <= PTCN14WW |
| Lenovo | Lenovo V14 G6 ITN BIOS | < RHCN20WW |
Showing 50 of 60 affected configurations. See the CNA advisory for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-10590?
How severe is CVE-2026-10590?
How do I fix CVE-2026-10590?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10585A stored cross-site scripting vulnerability was identified i…5.4
- CVE-2026-10586The Gutenberg Essential Blocks – Page Builder for Gutenberg …7.2
- CVE-2026-10587A potential out-of-bounds write vulnerability could allow a …6.8
- CVE-2026-10588A potential vulnerability could allow a local privileged att…6.7
- CVE-2026-10589A potential out of bounds write vulnerability could allow a …6.8
- CVE-2026-1059A security vulnerability has been detected in FeMiner wms up…9.8
- CVE-2026-10591Insufficient access control restrictions in the file write t…8.8
- CVE-2026-10592Certificates with wildcard DNS SANs (e.g. *.example.com) byp…5.3
- CVE-2026-10593The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unic…6.5
- CVE-2026-10595A path traversal vulnerability exists in parisneo/lollms ver…7.5
- CVE-2026-10597OMICARD EDM developed by ITPison has a Insecure Direct Objec…6.9
- CVE-2026-10599The Integrate PhonePe with WooCommerce WordPress plugin thro…7.5
Are you affected by CVE-2026-10590?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
