Skip to content
LenovoCVE-2026-16793

Lenovo XClarity Orchestrator: improper input validation

High8.7CVE-2026-16793 · Published Aug 4, 2026 · updated Aug 24, 2026

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.

Lenovo advisory

Affected versions

PackageAffectedFixed in
XClarity Orchestrator
Product
< 2.2.02.2.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20, CWE-78

More Lenovo advisories

All Lenovo
Advisory
Lenovo Dock Manager: arbitrary file write
Medium6.9Aug 13
Lenovo Vantage: code execution
High7.3Aug 13
Lenovo E14 Gen 6 Laptops ELAN TrackPoi: out-of-bounds write
Medium5.7Aug 13
Lenovo Vantage: arbitrary file write
Medium6.9Aug 13
Lenovo XClarity Essentials OneCLI: local low-privileged attacker could...
Low1.0Aug 4
Lenovo XClarity Orchestrator: improper certificate validation
High7.0Aug 4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.