A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-0421

CVE-2026-0421: Lenovo ThinkPad Auth Bypass Vulnerability

CVE-2026-0421 is an authentication bypass flaw in Lenovo ThinkPad BIOS that disables Secure Boot protection even when enabled. This article covers the technical details, affected ThinkPad models, security impact, and mitigation.

Updated: May 15, 2026

CVE-2026-0421 Overview

A BIOS vulnerability affects multiple Lenovo ThinkPad models, allowing Secure Boot to be silently disabled even when the BIOS setup menu reports it as enabled. The flaw exists in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads. The issue applies only to systems where Secure Boot is configured in User Mode. The vulnerability stems from an unchecked return value [CWE-252] during firmware initialization. An attacker with high local privileges can leverage this gap to load unsigned bootloaders and pre-boot malware that survive operating system reinstalls.

Critical Impact

Secure Boot can be bypassed on affected ThinkPads while the BIOS UI continues to report Secure Boot as active, enabling persistent bootkit installation.

Affected Products

  • Lenovo ThinkPad L13 Gen 6 and L13 Gen 6 2-in-1
  • Lenovo ThinkPad L14 Gen 6
  • Lenovo ThinkPad L16 Gen 2

Discovery Timeline

  • 2026-01-14 - CVE CVE-2026-0421 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2026-0421

Vulnerability Analysis

The vulnerability is a Secure Boot Bypass caused by an unchecked return value [CWE-252] in the affected ThinkPad BIOS. When Secure Boot is configured in User Mode, the firmware fails to validate the result of an internal status check before continuing the boot flow. As a result, Secure Boot enforcement is silently skipped while the BIOS setup menu continues to display the feature as On. This breaks the platform's chain of trust between firmware and the operating system loader. An attacker who achieves the necessary local privileges can install an unsigned UEFI bootloader, kernel driver, or bootkit that the platform should otherwise reject. Because the bypass occurs below the operating system, malicious code persists across OS reinstallation and is invisible to most endpoint controls.

Root Cause

The BIOS code path responsible for enforcing Secure Boot does not handle an error condition returned by a lower-level firmware routine. The missing check causes the platform to proceed as if Secure Boot validation succeeded.

Attack Vector

Exploitation requires local access and high privileges, along with user interaction such as a reboot. An attacker first stages a malicious bootloader on the EFI System Partition, then triggers a reboot. The affected BIOS loads the unsigned binary without verification while still reporting Secure Boot as enabled. Refer to the Lenovo Security Advisory LEN-210688 for technical details.

Detection Methods for CVE-2026-0421

Indicators of Compromise

  • Unsigned or unexpected .efi binaries present in the EFI System Partition, particularly under \EFI\BOOT\ or vendor directories.
  • BIOS setup screen reporting Secure Boot as On while operating system queries (such as Confirm-SecureBootUEFI on Windows or mokutil --sb-state on Linux) return inconsistent or disabled states.
  • Modifications to BIOS variables related to Secure Boot mode without a corresponding administrative change record.

Detection Strategies

  • Compare Secure Boot status reported by the BIOS against the value reported by the operating system on every boot, and alert on mismatches.
  • Inventory and hash EFI binaries on managed endpoints, then flag deviations from a known-good baseline.
  • Validate installed BIOS versions against the fixed releases listed in Lenovo advisory LEN-210688.

Monitoring Recommendations

  • Collect UEFI and Secure Boot telemetry from managed ThinkPads and forward it to a central analytics platform for correlation.
  • Monitor for unexpected reboots, BIOS configuration changes, and writes to the EFI System Partition.
  • Track BIOS update compliance on the affected ThinkPad models as a recurring security metric.

How to Mitigate CVE-2026-0421

Immediate Actions Required

  • Identify all L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads in the environment and prioritize them for BIOS updates.
  • Apply the fixed BIOS firmware published in Lenovo Security Advisory LEN-210688.
  • Restrict local administrative access on affected systems until firmware updates are deployed.
  • Verify Secure Boot status from the operating system after patching, rather than relying solely on the BIOS setup display.

Patch Information

Lenovo has published remediation guidance and fixed BIOS versions for the affected ThinkPad models in advisory LEN-210688. Administrators should deploy the updated firmware through Lenovo System Update, Lenovo Commercial Vantage, or enterprise software distribution tooling that supports BIOS provisioning.

Workarounds

  • Switch affected systems from Secure Boot User Mode to a configuration that is not impacted by the issue, where operationally feasible, until the BIOS update is applied.
  • Enable BIOS administrator passwords and disable boot from removable media to reduce the risk of local exploitation.
  • Use full-disk encryption with pre-boot authentication to limit an attacker's ability to stage malicious EFI binaries offline.
bash
# Verify Secure Boot status from the operating system
# Windows (PowerShell, run as Administrator)
Confirm-SecureBootUEFI

# Linux
mokutil --sb-state

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechThinkpad

  • SeverityHIGH

  • CVSS Score7.0

  • EPSS Probability0.02%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityHigh
  • AvailabilityHigh
  • CWE References
  • CWE-252
  • Technical References
  • Lenovo Security Advisory LEN-210688
  • Related CVEs
  • CVE-2026-0940: ThinkPad BIOS Privilege Escalation Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English