CVE-2026-16793
Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
| CWE | CWE-78 CWE-20 |
| Vendor | lenovo |
| Product | xclarity orchestrator |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for lenovo xclarity orchestrator
Be the first to know when new high vulnerabilities affecting lenovo xclarity orchestrator are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Lenovo / XClarity Orchestrator
0 < 2.2.0
References
Credits
Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.