Executive brief
Lenovo XClarity Orchestrator (LXCO) is a management platform for IT infrastructure and data center operations. An authenticated attacker can exploit improper input validation to execute arbitrary operating system commands with elevated privileges, potentially compromising the entire managed infrastructure and gaining control over critical systems.
Technical details
The vulnerability is a command injection flaw in XClarity Orchestrator 2.2.0, resulting from improper neutralization of special elements in operating system commands. An authenticated user can craft malicious input that is passed unsanitized to system command execution routines, allowing arbitrary code execution as a privileged process. The attack requires valid authentication credentials and knowledge of vulnerable input vectors. Successful exploitation grants attacker command execution at the system privilege level, enabling full system compromise. Patches should be available from Lenovo's support portal.
Affected products
- Lenovo XClarity Orchestrator 2.2.0
Timeline
- 2026-08-04: disclosed