A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.

Project Subscriptions

Vendors Products
Thinkpad L13 Gen 6 2 In 1 Bios Subscribe
Thinkpad L13 Gen 6 Bios Subscribe
Thinkpad L14 Gen 6 Bios Subscribe
Thinkpad L16 Gen 2 Bios Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update to the version (or higher) as recommended in the Product Impact section in the advisory:  https://support.lenovo.com/us/en/product_security/LEN-210688


Workaround

No workaround given by the vendor.

History

Sat, 18 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Title Lenovo BIOS Vulnerability Allowing Secure Boot Disablement

Thu, 15 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 22:30:00 +0000

Type Values Removed Values Added
Description A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads which could result in Secure Boot being disabled even when configured as “On” in the BIOS setup menu. This issue only affects systems where Secure Boot is set to User Mode.
First Time appeared Lenovo
Lenovo thinkpad L13 Gen 6 2 In 1 Bios
Lenovo thinkpad L13 Gen 6 Bios
Lenovo thinkpad L14 Gen 6 Bios
Lenovo thinkpad L16 Gen 2 Bios
Weaknesses CWE-252
CPEs cpe:2.3:a:lenovo:thinkpad_l13_gen_6_2_in_1_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_l13_gen_6_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_l14_gen_6_bios:*:*:*:*:*:*:*:*
cpe:2.3:a:lenovo:thinkpad_l16_gen_2_bios:*:*:*:*:*:*:*:*
Vendors & Products Lenovo
Lenovo thinkpad L13 Gen 6 2 In 1 Bios
Lenovo thinkpad L13 Gen 6 Bios
Lenovo thinkpad L14 Gen 6 Bios
Lenovo thinkpad L16 Gen 2 Bios
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-02-26T15:04:07.954Z

Reserved: 2025-12-04T19:05:55.282Z

Link: CVE-2026-0421

cve-icon Vulnrichment

Updated: 2026-01-15T13:54:33.827Z

cve-icon NVD

Status : Deferred

Published: 2026-01-14T23:15:56.397

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-0421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T16:15:04Z

Weaknesses