CVE-2026-16792
6.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Summary
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Lenovo | XClarity Orchestrator | 0 <= 2.2.0 | affected |
Weaknesses
- CWE-295: CWE-295 Improper certificate validation
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.