CVE-2026-16792: Lenovo Xclarity Orchestrator

Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.

Affected products

  • Lenovo Xclarity Orchestrator: up to and including 2.2.0

Published 2026-08-04. Last modified 2026-08-24.