Lenovo XClarity Orchestrator是中国Lenovo公司的一款服务器集群编排管理软件。 Lenovo XClarity Orchestrator 2.2.0版本存在安全漏洞,该漏洞源于对操作系统命令的特殊元素中和不当,可能允许经过身份验证的攻击者在特定情况下以特权用户身份执行任意操作系统命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Lenovo | XClarity Orchestrator | < 2.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Lenovo | XClarity Orchestrator | 0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16792 | 6.1 MEDIUM | Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator |
| CVE-2026-16791 | 3.9 LOW | Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI |
No comments yet