AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16793

HIGH · CVSS 8.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Lenovo XClarity Orchestrator version 2.2.0 is vulnerable to an improper neutralization of special elements in operating system commands, enabling authenticated attackers to execute arbitrary commands with elevated privileges. This vulnerability poses a significant risk as it can lead to unauthorized access and control over the system. Organizations using this software should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-16793
Severity
HIGH
CVSS
8.8
EPSS
0.36%

Original NVD Description

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.