CVE-2026-14371
HIGHLenovo XClarity Integrator For Microsoft Windows Admin Center - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Title source: ruleDescription
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://pcsupport.lenovo.com/us/en/product_security/home
Scores
CVSS v4
8.8
EPSS
0.0076
EPSS Percentile
51.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
Lenovo/XClarity Integrator for Microsoft Windows Admin Center
4.7.1 - 5.1.1
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026