Improper Neutralization Vulnerability in Lenovo XClarity Orchestrator
CVE-2026-16793
8.7HIGH
What is CVE-2026-16793?
The Lenovo XClarity Orchestrator 2.2.0 is exposed to a vulnerability that arises from improper neutralization of special elements utilized in operating system commands. This issue can be exploited by an authenticated attacker to execute arbitrary commands with elevated privileges under certain conditions. It is imperative for users to assess their systems and apply relevant patches to mitigate potential risks.
Affected Version(s)
XClarity Orchestrator x86 0 < 2.2.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.