An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Advisories
No advisories yet.
Fixes
Solution
Update Lenovo XClarity Orchestrator to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance. | |
| Title | Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator | |
| First Time appeared |
Lenovo
Lenovo xclarity Orchestrator |
|
| Weaknesses | CWE-20 CWE-78 |
|
| CPEs | cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:linux:*:*:*:*:* cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:x86:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo xclarity Orchestrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-08-04T19:48:11.325Z
Reserved: 2026-07-23T18:03:50.157Z
Link: CVE-2026-16793
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T21:30:12Z