GPU VulnDB

Database/Firmware, BMC & network fabric

Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management traffic

CVE-2026-16792Firmware, BMC & network fabriccurated

Impact

XClarity Orchestrator aggregates out-of-band management for Lenovo server fleets and holds the credentials it uses to drive XCC BMCs. Several 2.2.0 microservices do not properly validate TLS certificates, so an attacker positioned on the management network can machine-in-the-middle those HTTPS connections and read what crosses them. Lenovo qualifies this as happening 'under certain circumstances' and does not enumerate which microservices or which flows are affected, so treat exposure of management credentials as plausible rather than established. In a datacenter that runs out-of-band management flat across racks, this is exactly the segment an attacker with one rack-level foothold would be sitting on.

Who can reach it

Adjacent network - an attacker able to position on the management network segment LXCO uses. No authentication to LXCO is required.

What to do

Upgrade XClarity Orchestrator per Lenovo advisory HT509976 and restart the appliance; the NVD record does not name the fixed build, so take the version from Lenovo's page. This touches management-plane software only - no BMC or server firmware flash, no node reboot, no drain. Until the upgrade lands, the mitigation is network-level: keep the management VLAN isolated from tenant and general corporate traffic.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.