๐Ÿ” CVE Alert

CVE-2026-16792

MEDIUM 6.1

Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.

CWE CWE-295
Vendor lenovo
Product xclarity orchestrator
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for lenovo xclarity orchestrator

Be the first to know when new medium vulnerabilities affecting lenovo xclarity orchestrator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Lenovo / XClarity Orchestrator
0 โ‰ค 2.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.lenovo.com: https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator

Credits

Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.