CVE-2026-16793: Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator
Published Aug 4, 2026
·Updated
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
Affected Software
1 affected component
Lenovo XClarity Orchestrator (LXCO)=2.2.0
Event History
Aug 4, 2026
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness