OS Command Injection in Lenovo XClarity Orchestrator
Lenovo XClarity Orchestrator (LXCO) versions prior to 2.2.0 contain an OS command injection vulnerability (CVE-2026-16793) allowing authenticated attackers to execute arbitrary commands with high privileges.
Lenovo has identified a critical OS command injection vulnerability, tracked as CVE-2026-16793, affecting Lenovo XClarity Orchestrator (LXCO) versions earlier than 2.2.0. This vulnerability, categorized under CWE-78 (Improper Neutralization of Special Elements used in an OS Command), occurs due to insufficient input validation of user-supplied data. An attacker who has already authenticated to the LXCO management interface can leverage this flaw to execute arbitrary operating system commands with elevated privileges. Given the nature of LXCO as a management tool for IT infrastructure, this vulnerability presents a significant risk, potentially leading to full system compromise of the orchestrator, which could then be used as a pivot point for further lateral movement within the data center environment.
Impact
Successful exploitation of this vulnerability allows an authenticated attacker to achieve code execution as a privileged user on the LXCO instance. This grants the attacker complete control over the appliance, enabling data exfiltration, service disruption, and the ability to manipulate the managed infrastructure overseen by the orchestrator.
Recommendation
Prioritized actions for security and IT teams:
- Upgrade all instances of Lenovo XClarity Orchestrator to version 2.2.0 or later to remediate CVE-2026-16793.
- Implement strict access control for the LXCO management interface, limiting access to a subset of trusted administrative IP addresses to reduce the likelihood of unauthorized authentication.
- Review audit logs for the LXCO management web interface for suspicious commands or anomalous parameter values following an authenticated session.
Immediate actions
Upgrade Lenovo XClarity Orchestrator to 2.2.0 or later
Mitigations
Restrict network access to the LXCO web management interface
CVE-2026-16793