Skip to content
LenovoCVE-2026-14371

Lenovo XClarity Integrator for Microsoft Windows Admin Center: command injection

High8.8CVE-2026-14371 · Published Jul 16, 2026

The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.

Lenovo advisory

Affected versions

PackageAffectedFixed in
XClarity Integrator for Microsoft Windows Admin Center
Product
>= 4.7.1, <= 5.1.1No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More Lenovo advisories

All Lenovo
Advisory
Lenovo Legion Zone: insecure permissions
High7.3Jul 16
Lenovo Smart Connect: improper access control
Medium6.8Jul 16
Lenovo App Store: code execution
High7.0Jul 16
Lenovo IdeaPad Pro 5 16AGP11 BIOS: out-of-bounds write
Medium6.8Jul 16
Lenovo IdeaPad Pro 5 16AGP11 BIOS: missing authentication
Medium6.7Jul 16
Lenovo App Store: path traversal
High7.0Jul 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.