Skip to content
LenovoCVE-2026-16792

Lenovo XClarity Orchestrator: improper certificate validation

High7.0CVE-2026-16792 · Published Aug 4, 2026 · updated Aug 24, 2026

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.

Lenovo advisory

Affected versions

PackageAffectedFixed in
XClarity Orchestrator
Product
<= 2.2.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-295

More Lenovo advisories

All Lenovo
Advisory
Lenovo Dock Manager: arbitrary file write
Medium6.9Aug 13
Lenovo Vantage: code execution
High7.3Aug 13
Lenovo E14 Gen 6 Laptops ELAN TrackPoi: out-of-bounds write
Medium5.7Aug 13
Lenovo Vantage: arbitrary file write
Medium6.9Aug 13
Lenovo XClarity Essentials OneCLI: local low-privileged attacker could...
Low1.0Aug 4
Lenovo XClarity Orchestrator: improper input validation
High8.7Aug 4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.