An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance. | |
| Title | Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator | |
| First Time appeared |
Lenovo
Lenovo xclarity Orchestrator |
|
| Weaknesses | CWE-20 CWE-78 |
|
| CPEs | cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:linux:*:*:*:*:* cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:x86:*:*:*:*:* |
|
| Vendors & Products |
Lenovo
Lenovo xclarity Orchestrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published: 2026-08-04T19:48:11.325Z
Updated: 2026-08-05T14:48:38.793Z
Reserved: 2026-07-23T18:03:50.157Z
Link: CVE-2026-16793
Updated: 2026-08-05T14:48:35.407Z
No data.
No data.