CVE-2026-16793: Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator
Published Aug 4, 2026
·Updated
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Affected Software
1 affected component
Lenovo XClarity Orchestrator (LXCO)=2.2.0
Event History
Aug 4, 2026
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16793?
CVE-2026-16793 has a high severity rating of 8.7.
2
How do I fix CVE-2026-16793?
To fix CVE-2026-16793, update Lenovo XClarity Orchestrator to the latest version that addresses this vulnerability.
3
What is the risk associated with CVE-2026-16793?
CVE-2026-16793 has a risk score of 79, indicating it poses a significant security threat.
4
Who is affected by CVE-2026-16793?
CVE-2026-16793 affects users of Lenovo XClarity Orchestrator version 2.2.0.
5
What type of vulnerability is CVE-2026-16793?
CVE-2026-16793 is categorized as an OS Command Injection vulnerability.