Description
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
Published: 2026-07-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Lenovo XClarity Integrator for Microsoft Windows Admin Center plugin, versions 5.1.1 and earlier, allows PowerShell Command Injection when establishing remote PowerShell commands. This vulnerability matches CWE-78 and enables an attacker to execute arbitrary commands on the host running the Windows Admin Center gateway, potentially compromising confidentiality, integrity, and availability of the system and any resources it manages.

Affected Systems

Lenovo XClarity Integrator for Microsoft Windows Admin Center, version 5.1.1 and earlier, when installed on the Windows Admin Center gateway.

Risk and Exploitability

With a CVSS score of 8.8, this flaw is considered high severity. The EPSS score of <1% indicates a low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via PowerShell commands executed through the Windows Admin Center gateway. An attacker with the ability to send or manipulate such remote PowerShell commands could gain full control over the underlying system, and due to the lack of current exploitation data the exploitation remains undetected in the public domain as of this analysis.

Generated by OpenCVE AI on July 31, 2026 at 01:37 UTC.

Remediation

Vendor Solution

Update XClarity Integrator for Microsoft Windows Admin Center to version 5.2 or later.


OpenCVE Recommended Actions

  • Upgrade the XClarity Integrator for Microsoft Windows Admin Center to version 5.2 or later.
  • If an upgrade is not immediately possible, restrict or disable remote PowerShell command functionality on the Windows Admin Center gateway to prevent injection attacks.
  • Continuously monitor Windows Admin Center logs for suspicious PowerShell activity and enforce network segmentation to limit potential lateral movement.

Generated by OpenCVE AI on July 31, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title PowerShell Command Injection in Lenovo XClarity Integrator for Windows Admin Center

Fri, 24 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title PowerShell Command Injection in Lenovo XClarity Integrator for Windows Admin Center

Fri, 17 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title PowerShell Command Injection in Lenovo XClarity Integrator for Windows Admin Center

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
First Time appeared Lenovo
Lenovo xclarity Integrator For Microsoft Windows Admin Center
Weaknesses CWE-78
CPEs cpe:2.3:a:lenovo:xclarity_integrator_for_microsoft_windows_admin_center:*:*:windows:*:*:*:*:*
Vendors & Products Lenovo
Lenovo xclarity Integrator For Microsoft Windows Admin Center
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Lenovo Xclarity Integrator For Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2026-07-16T17:36:41.747Z

Reserved: 2026-07-01T19:52:49.119Z

Link: CVE-2026-14371

cve-icon Vulnrichment

Updated: 2026-07-16T17:36:04.435Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:45:06Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')