securityonline.info 9/2/2026, 4:47:22 PM · external

Dropbox Lenovo ID Flaw Let Attackers Hijack Accounts by Email

Dropbox Lenovo ID Flaw Let Attackers Hijack Accounts by Email

A recent security flaw affected Dropbox users due to a vulnerability in the Lenovo ID registration process, allowing unauthorized access to Dropbox accounts just by using a victim's email address. Attackers exploited an email-verification defect in Lenovo ID, enabling them to create an account without verification. This flaw was further exacerbated by Dropbox's SSO mechanism which matched accounts solely by email, allowing attackers to gain complete control without needing a password.

Dropbox has since revoked all sessions linked to Lenovo ID and changed its login process to require Dropbox passwords for verification. Affected accounts were investigated, revealing that less than a third had files accessed.

View full article

Article by CyberSIXT