Database/Firmware, BMC & network fabric
Lenovo XClarity Orchestrator (OS command injection): An authenticated attacker executes arbitrary OS commands
CVE-2026-16793Firmware, BMC & network fabriccurated
Impact
An authenticated attacker executes arbitrary OS commands as a privileged user on LXCO. Orchestrator sits above XClarity Administrator and drives multi-site fleet management, so compromise there reaches a very large number of servers.
Who can reach it
Authenticated low-privilege access to LXCO 2.2.0.
What to do
Apply the Lenovo LXCO update. Appliance upgrade with a service restart; rotate the credentials LXCO uses to reach managed XCC endpoints afterwards.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.