Executive brief
Lenovo XClarity Orchestrator is a management platform used to oversee data center infrastructure. A flaw in how it validates TLS certificates in microservices could allow an attacker on the same local network to intercept encrypted communications between system components, potentially exposing sensitive management credentials or operational data.
Technical details
The vulnerability is an improper certificate validation flaw affecting multiple microservices in LXCO 2.2.0. The root cause involves insufficient validation of TLS certificates during HTTPS connections, which an adjacent network attacker can exploit to perform a man-in-the-middle attack. The attack requires the attacker to be on the same network segment or adjacent network and does not require prior authentication. Successful exploitation allows interception and potential modification of encrypted management traffic. Patches or mitigations were available as of the publication date (August 2026).
Affected products
- Lenovo XClarity Orchestrator 2.2.0
Timeline
- 2026-08-04: disclosed