Database/Firmware, BMC & network fabric
Lenovo XClarity Integrator for Windows Admin Center (PowerShell command injection): PowerShell command injection
CVE-2026-14371Firmware, BMC & network fabriccurated
Impact
PowerShell command injection on the Windows Admin Center gateway when establishing remote commands - code execution on a host that holds administrative reach into the managed estate.
Who can reach it
Authenticated low-privilege access to the WAC gateway, with user interaction.
What to do
Upgrade the XClarity Integrator WAC plugin past 5.1.1. Plugin update on the gateway host.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.