{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-16793", "assignerOrgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b", "state": "PUBLISHED", "assignerShortName": "lenovo", "dateReserved": "2026-07-23T18:03:50.157Z", "datePublished": "2026-08-04T19:48:11.325Z", "dateUpdated": "2026-08-05T14:48:38.793Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "da227ddf-6e25-4b41-b023-0f976dcaca4b", "shortName": "lenovo", "dateUpdated": "2026-08-04T19:48:11.325Z" }, "title": "Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator", "datePublic": "2026-08-04T13:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-78", "description": "CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-20", "description": "CWE-20 Improper input validation", "type": "CWE" } ] } ], "affected": [ { "vendor": "Lenovo", "product": "XClarity Orchestrator", "platforms": [ "x86", "Linux" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "2.2.0", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "cpeApplicability": [ { "operator": "OR", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:x86:*:*:*:*:*", "versionStartIncluding": "0", "versionEndExcluding": "2.2.0" }, { "vulnerable": true, "criteria": "cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:linux:*:*:*:*:*", "versionStartIncluding": "0", "versionEndExcluding": "2.2.0" } ] } ] } ], "descriptions": [ { "lang": "en", "value": "An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance." } ] } ], "references": [ { "url": "https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator", "tags": [ "product", "patch", "release-notes" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "HIGH", "baseScore": 8.8, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "HIGH", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "HIGH", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 8.7, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } } ], "solutions": [ { "lang": "en", "value": "Update Lenovo XClarity Orchestrator to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Update Lenovo XClarity Orchestrator to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433" } ] } ], "credits": [ { "lang": "en", "value": "Lenovo thanks Christopher Lusk of North Echo Security Research for reporting this vulnerability.", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.0-beta" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-05T14:48:32.123950Z", "id": "CVE-2026-16793", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-05T14:48:38.793Z" } } ] } }