GPU VulnDB

Database/Firmware, BMC & network fabric

Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commands

CVE-2026-16793Firmware, BMC & network fabriccurated

Impact

An authenticated attacker executes arbitrary OS commands as a privileged user on LXCO. Orchestrator sits above XClarity Administrator and drives multi-site fleet management, so compromise there reaches a very large number of servers.

Who can reach it

Authenticated low-privilege access to LXCO 2.2.0.

What to do

Apply the Lenovo LXCO update. Appliance upgrade with a service restart; rotate the credentials LXCO uses to reach managed XCC endpoints afterwards.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.