GPU VulnDB

Database/Firmware, BMC & network fabric

Lenovo XClarity OneCLI: temp file handling lets a local user overwrite files when the tool runs elevated

CVE-2026-16791Firmware, BMC & network fabriccurated

Impact

OneCLI is the tool operators run on Lenovo servers to inventory hardware, apply firmware updates and push BMC/UEFI settings, and it is normally invoked as root. Its temporary file creation on Linux lets an unprivileged local account on the same host cause OneCLI to overwrite or truncate arbitrary files with data the program itself generates. The attacker does not choose the content, so this is a corruption and denial-of-service primitive rather than a direct route to code execution - but on a management or provisioning host that runs firmware jobs for a fleet, destroying the wrong file can take out the tooling that drains and reflashes nodes. Lenovo scores it 1.0: it needs a local foothold and it needs an administrator to run OneCLI while the attacker is positioned.

Who can reach it

A local, authenticated low-privileged user on the Linux host where OneCLI is installed. Exploitation depends on an elevated OneCLI run happening (user interaction is in the vector), so the exposure is on shared management or bastion hosts rather than on a single-admin box.

What to do

Lenovo lists 5.5.0 and below as affected; upgrade to the fixed OneCLI release named in HT116433 - the record does not state the version number, so read it off the advisory. This is a management utility, not a daemon: replacing the binary needs no server downtime, no firmware flash and no node reboot. Interim mitigation is to stop non-administrators from having shell access on hosts where OneCLI is run elevated.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.