{"id":"CVE-2026-16793","published":"2026-08-04T20:16:49.463","lastModified":"2026-08-05T16:16:53.400","description":"An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-20","CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://support.lenovo.com/my/en/solutions/ht509976-lenovo-xclarity-orchestrator","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an authenticated attacker to execute arbitrary OS commands as a privileged user in Lenovo XClarity Orchestrator 2.2.0, potentially leading to full system compromise.","exploitability":"Exploitation requires authentication and specific circumstances but is considered high risk due to the elevated privileges gained.","blast_radius":"If exploited, this could lead to complete control over the affected system, impacting data security and integrity.","remediation":"Update Lenovo XClarity Orchestrator to the latest version or apply vendor-provided patches immediately.","tags":["rce","auth-required","os-command-injection","patch-available"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:46:33.162Z"}}