LenovoCVE-2026-14371
Lenovo XClarity Integrator for Microsoft Windows Admin Center: command injection
High8.8CVE-2026-14371 · Published Jul 16, 2026
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| XClarity Integrator for Microsoft Windows Admin Center Product | >= 4.7.1, <= 5.1.1 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Lenovo advisories
All Lenovo| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 16 | Lenovo Legion Zone: insecure permissions | High7.3 | 2.0.26+1 more |
| Jul 16 | Lenovo Smart Connect: improper access control | Medium6.8 | 09.0.2.003.000 |
| Jul 16 | Lenovo App Store: code execution | High7.0 | 9.0.2930.0514 |
| Jul 16 | Lenovo IdeaPad Pro 5 16AGP11 BIOS: out-of-bounds write | Medium6.8 | Yoga Pro 7 15IPH11 BIOS TNCN37WW+5 more |
| Jul 16 | Lenovo IdeaPad Pro 5 16AGP11 BIOS: missing authentication | Medium6.7 | Yoga Pro 7 15IPH11 BIOS TNCN37WW+5 more |
| Jul 16 | Lenovo App Store: path traversal | High7.0 | 9.0.2930.0514 |