CVE-2026-16792
MEDIUM
NVD
CVSS Score
6.1
Severity
MEDIUM
Published
Aug 04, 2026
Vendor
unknown
Description
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS certificate validation under certain circumstances.