CVE-2026-16792
EUVD-2026-5288504.08.2026, 20:16
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| lenovo | xclarity_orchestrator | 𝑥 ≤ 2.2.0 | CNA |
Common Weakness Enumeration