CVE-2026-16792
Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.
| CWE | CWE-295 |
| Vendor | lenovo |
| Product | xclarity orchestrator |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for lenovo xclarity orchestrator
Be the first to know when new medium vulnerabilities affecting lenovo xclarity orchestrator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Lenovo / XClarity Orchestrator
0 โค 2.2.0
References
Credits
Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.