๐Ÿ” CVE Alert

CVE-2026-16793

HIGH 8.8

Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.

CWE CWE-78 CWE-20
Vendor lenovo
Product xclarity orchestrator
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for lenovo xclarity orchestrator

Be the first to know when new high vulnerabilities affecting lenovo xclarity orchestrator are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Lenovo / XClarity Orchestrator
0 < 2.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.lenovo.com: https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator

Credits

Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.