Improper Certificate Validation in Lenovo XClarity Orchestrator Microservices
CVE-2026-16792

7HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
4 August 2026

What is CVE-2026-16792?

An improper certificate validation vulnerability has been identified in Lenovo XClarity Orchestrator 2.2.0 microservices. This flaw could enable an adjacent network attacker to intercept sensitive communications by executing a machine-in-the-middle attack against HTTPS connections, particularly during the TLS certificate validation process under specific conditions. Users should be aware of this vulnerability and consider applying security patches to mitigate the risk of unauthorized access.

Affected Version(s)

XClarity Orchestrator x86 0 <= 2.2.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.
.