CVE-2026-18058 PUBLISHED

Assigner: lenovo
Reserved: 28.07.2026 Published: 02.09.2026 Updated: 02.09.2026

The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 7.3

Product Status

Vendor Motorola
Product Smart Connect Application
Versions Default: unaffected
  • affected from 0 to 9.03.00.61 (excl.)

Solutions

Please ensure your SmartConnect application is on version tag 9.03.00.61, and that you have the latest monthly security patches for your device.

References

Problem Types

  • CWE-862: Missing Authorization CWE