CVE-2026-0421 PUBLISHED

Assigner: lenovo
Reserved: 04.12.2025 Published: 14.01.2026 Updated: 26.02.2026

A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7

Product Status

Vendor Lenovo
Product ThinkPad L13 Gen 6 BIOS
Versions Default: unaffected
  • affected from 0 to 1.10 (excl.)
Vendor Lenovo
Product ThinkPad L13 Gen 6 2 in 1 BIOS
Versions Default: unaffected
  • affected from 0 to 1.10 (excl.)
Vendor Lenovo
Product ThinkPad L14 Gen 6 BIOS
Versions Default: unaffected
  • affected from 0 to 1.06 (excl.)
Vendor Lenovo
Product ThinkPad L16 Gen 2 BIOS
Versions Default: unaffected
  • affected from 0 to 1.06 (excl.)

Solutions

Update to the version (or higher) as recommended in the Product Impact section in the advisory:  https://support.lenovo.com/us/en/product_security/LEN-210688

References

Problem Types

  • CWE-252: Unchecked Return Value CWE