Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Lenovo XClarity Orchestrator to the version indicated in the advisory or higher - https://support.lenovo.com/us/en/solutions/ht116433
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances. | |
| Title | Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator | |
| First Time appeared |
Lenovo
Lenovo xclarity Orchestrator |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:lenovo:xclarity_orchestrator:*:*:x86:*:*:*:*:* | |
| Vendors & Products |
Lenovo
Lenovo xclarity Orchestrator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2026-08-04T19:48:03.197Z
Reserved: 2026-07-23T18:03:48.528Z
Link: CVE-2026-16792
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T21:30:12Z