CVE-2026-14371

HIGH

Lenovo XClarity Integrator For Microsoft Windows Admin Center - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Title source: rule
STIX 2.1

Description

The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.

References (1)

Core 1
Core References

Scores

CVSS v4 8.8
EPSS 0.0076
EPSS Percentile 51.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Lenovo/XClarity Integrator for Microsoft Windows Admin Center 4.7.1 - 5.1.1
Published Jul 16, 2026
Tracked Since Jul 16, 2026