Database/Firmware, BMC & network fabric
Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commands
CVSS 8.8CVE-2026-16793Firmware, BMC & network fabriccurated
Impact
An authenticated attacker executes arbitrary OS commands as a privileged user on LXCO. Orchestrator sits above XClarity Administrator and drives multi-site fleet management, so compromise there reaches a very large number of servers.
Who can reach it
Authenticated low-privilege access to LXCO 2.2.0.
What to do
Apply the Lenovo LXCO update. Appliance upgrade with a service restart; rotate the credentials LXCO uses to reach managed XCC endpoints afterwards.
References
Related entries
- Eaton Tripp Lite series PADM firmware, session management interface: A low-privilege authenticated user escalatesCVE-2026-22622 · Eaton Tripp Lite series PADM firmware, session management interfaceHigh
- NVIDIA UFM Enterprise: web interface authorization flaw leads to code execution on the fabric managerCVE-2026-24170 · NVIDIA UFM Enterprise (web interface authorization)High
- Linux kernel (drivers/infiniband/core): The RDMA user-capability check identified the capability file only by deviceCVE-2026-53188 · Linux kernel (drivers/infiniband/core)High
- Dell OpenManage Enterprise: authenticated low-privilege OS command injection on the management applianceCVE-2026-54795 · Dell OpenManage Enterprise (OS command injection)High
- Linux kernel mlx5_core IPsec offload / eswitch mode interlock: The acquire-SA path unconditionally callsCVE-2026-64522 · Linux kernel mlx5_core IPsec offload / eswitch mode interlockHigh
- MikroTik RouterOS: pre-auth btest session leaks kernel buffer data and can restart the deviceCVE-2026-67277 · MikroTik RouterOS (btest bandwidth test service)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.