Executive brief
Lenovo XClarity Integrator is a tool used by IT administrators to manage and monitor Lenovo hardware through the Microsoft Windows Admin Center. A security flaw in this tool allows an attacker to inject malicious commands into the system when remote management tasks are being performed. If exploited, this could allow an attacker to take full control of the management gateway, potentially leading to a total compromise of the managed infrastructure and sensitive data.
Technical details
A PowerShell command injection vulnerability (CWE-78) exists in the Lenovo XClarity Integrator for Windows Admin Center (WAC) plugin versions 5.1.1 and below. The flaw occurs during the establishment of remote PowerShell sessions, where the application fails to properly neutralize special elements used in OS commands. An attacker with low-level privileges and network access can exploit this by providing crafted input that is executed with higher privileges on the WAC Gateway. Successful exploitation requires some user interaction and can result in complete compromise of confidentiality, integrity, and availability across the affected system and its managed environment.
Affected products
- Lenovo XClarity Integrator for Microsoft Windows Admin Center 4.7.1 through 5.1.1
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory