Improper Neutralization Vulnerability in Lenovo XClarity Orchestrator
CVE-2026-16793

8.7HIGH

Key Information:

Vendor

Lenovo

Vendor
CVE Published:
4 August 2026

What is CVE-2026-16793?

The Lenovo XClarity Orchestrator 2.2.0 is exposed to a vulnerability that arises from improper neutralization of special elements utilized in operating system commands. This issue can be exploited by an authenticated attacker to execute arbitrary commands with elevated privileges under certain conditions. It is imperative for users to assess their systems and apply relevant patches to mitigate potential risks.

Affected Version(s)

XClarity Orchestrator x86 0 < 2.2.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.
.