Database/Firmware, BMC & network fabric
Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injection
CVSS 8.8CVE-2026-14371Firmware, BMC & network fabriccurated
Impact
PowerShell command injection on the Windows Admin Center gateway when establishing remote commands - code execution on a host that holds administrative reach into the managed estate.
Who can reach it
Authenticated low-privilege access to the WAC gateway, with user interaction.
What to do
Upgrade the XClarity Integrator WAC plugin past 5.1.1. Plugin update on the gateway host.
References
Related entries
- OpenBMC phosphor-net-ipmid: session authorization can be swapped to another account without re-authenticatingCVE-2026-16140 · OpenBMC phosphor-net-ipmid (IPMI 2.0 RAKP session authorization)High
- Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commandsCVE-2026-16793 · Lenovo XClarity Orchestrator (OS command injection)High
- Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesCVE-2026-22622 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerCVE-2026-24170 · NVIDIA UFM Enterprise (web interface authorization)High
- Linux kernel (drivers/infiniband/core): The RDMA user-capability check identified the capability file only by deviceCVE-2026-53188 · Linux kernel (drivers/infiniband/core)High
- Dell OpenManage Enterprise: authenticated low-privilege OS command injection on the management applianceCVE-2026-54795 · Dell OpenManage Enterprise (OS command injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.