Improper Certificate Validation in Lenovo XClarity Orchestrator Microservices
CVE-2026-16792
7HIGH
What is CVE-2026-16792?
An improper certificate validation vulnerability has been identified in Lenovo XClarity Orchestrator 2.2.0 microservices. This flaw could enable an adjacent network attacker to intercept sensitive communications by executing a machine-in-the-middle attack against HTTPS connections, particularly during the TLS certificate validation process under specific conditions. Users should be aware of this vulnerability and consider applying security patches to mitigate the risk of unauthorized access.
Affected Version(s)
XClarity Orchestrator x86 0 <= 2.2.0
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.