LenovoCVE-2026-16792
Lenovo XClarity Orchestrator: improper certificate validation
High7.0CVE-2026-16792 · Published Aug 4, 2026 · updated Aug 24, 2026
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| XClarity Orchestrator Product | <= 2.2.0 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-295
More Lenovo advisories
All Lenovo| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 13 | Lenovo Dock Manager: arbitrary file write | Medium6.9 | 1.6.5.3 |
| Aug 13 | Lenovo Vantage: code execution | High7.3 | 20.2026.20.0+1 more |
| Aug 13 | Lenovo E14 Gen 6 Laptops ELAN TrackPoi: out-of-bounds write | Medium5.7 | E16 Gen 2 (Type 21M5+3 more |
| Aug 13 | Lenovo Vantage: arbitrary file write | Medium6.9 | 1.1.0.51 |
| Aug 4 | Lenovo XClarity Essentials OneCLI: local low-privileged attacker could... | Low1.0 | 5.6 |
| Aug 4 | Lenovo XClarity Orchestrator: improper input validation | High8.7 | 2.2.0 |