What is CVE-2026-16792?
CVE-2026-16792: An improper certificate validation vulnerability was found in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices. This could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate exchange. Affected LXCO 2.2.0 microservices should apply the vendor-provided updates or mitigations as soon as possible.
Azərbaycanca: CVE-2026-16792: Lenovo XClarity Orchestrator (LXCO) 2.2.0-da düzgün olmayan sertifikat doğrulaması zəifliyi aşkar edilib. Bu, yaxınlıqdakı şəbəkə təcavüzkarına TLS sertifikat mübadiləsi zamanı HTTPS bağlantılarına qarşı ortadakı adam (machine-in-the-middle) hücumu həyata keçirərək həssas kommunikasiyaları ələ keçirməyə imkan verə bilər. Təsirə məruz qalan LXCO 2.2.0 mikroxidmətləri üçün istehsalçı tərəfindən təqdim olunan yeniləmələr və ya azaldıcı tədbirlər tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which version of Lenovo XClarity Orchestrator is affected by the CVE-2026-16792 vulnerability?
This vulnerability affects the microservices in Lenovo XClarity Orchestrator (LXCO) version 2.2.0.
What type of attack can an attacker perform by exploiting the CVE-2026-16792 vulnerability?
An adjacent network attacker can perform a machine-in-the-middle attack against HTTPS connections during TLS certificate exchange to intercept sensitive communications.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.