AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16792

MEDIUM · CVSS 6.1 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices are vulnerable due to improper certificate validation, which could enable an adjacent network attacker to execute a machine-in-the-middle attack, potentially intercepting sensitive communications. Organizations using these microservices should prioritize addressing this vulnerability to safeguard their data integrity and confidentiality during HTTPS connections. Immediate action is recommended for those managing network security in environments utilizing LXCO.

CVE
CVE-2026-16792
Severity
MEDIUM
CVSS
6.1
EPSS
0.07%

Original NVD Description

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.