[WID-SEC-2026-2660] Lenovo XClarity Orchestrator: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen und Codeausführung CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 04.08.2026 Stand 05.08.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Windows Produktbeschreibung Lenovo XClarity ist ein Verwaltungswerkzeug für Rechenzentren. Produkte 04.08.2026 Lenovo XClarity Orchestrator <2.2.1 GA FIX Angriff Angriff Ein Angreifer aus einem angrenzenden Netzwerk kann mehrere Schwachstellen in Lenovo XClarity Orchestrator ausnutzen, um Informationen offenzulegen oder beliebige Betriebssystembefehle als privilegierter Benutzer auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in Lenovo XClarity Orchestrator (CVSS 8.8) allow an attacker from an adjacent network to disclose information or execute arbitrary operating system commands as a privileged user. The flaw affects versions prior to 2.2.1 GA, and Lenovo has provided a mitigation.