LenovoCVE-2026-16793
Lenovo XClarity Orchestrator: improper input validation
High8.7CVE-2026-16793 · Published Aug 4, 2026 · updated Aug 24, 2026
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| XClarity Orchestrator Product | < 2.2.0 | 2.2.0 |
Details and references
More Lenovo advisories
All Lenovo| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 13 | Lenovo Dock Manager: arbitrary file write | Medium6.9 | 1.6.5.3 |
| Aug 13 | Lenovo Vantage: code execution | High7.3 | 20.2026.20.0+1 more |
| Aug 13 | Lenovo E14 Gen 6 Laptops ELAN TrackPoi: out-of-bounds write | Medium5.7 | E16 Gen 2 (Type 21M5+3 more |
| Aug 13 | Lenovo Vantage: arbitrary file write | Medium6.9 | 1.1.0.51 |
| Aug 4 | Lenovo XClarity Essentials OneCLI: local low-privileged attacker could... | Low1.0 | 5.6 |
| Aug 4 | Lenovo XClarity Orchestrator: improper certificate validation | High7.0 | No fix yet |