← Back

CVE-2026-21837

nvd nist
Published: Jun 5, 2026Modified: Jun 10, 2026

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: psirt@hcl.com (Secondary)

Description

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

Affected (67)

2 products
Digital Experience
Digital Experience Compose
Configuration A
55 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Version 9.5
Version 9.5 cf171
Version 9.5 cf172
Version 9.5 cf173
Version 9.5 cf17
Version 9.5 cf181
Version 9.5 cf182
Version 9.5 cf183
Version 9.5 cf184
Version 9.5 cf18
Version 9.5 cf191
Version 9.5 cf192
Version 9.5 cf193
Version 9.5 cf194
Version 9.5 cf195
Version 9.5 cf196
Version 9.5 cf197
Version 9.5 cf198
Version 9.5 cf199
Version 9.5 cf19
Version 9.5 cf200
Version 9.5 cf201
Version 9.5 cf202
Version 9.5 cf203
Version 9.5 cf204
Version 9.5 cf205
Version 9.5 cf206
Version 9.5 cf207
Version 9.5 cf208
Version 9.5 cf209
Version 9.5 cf210
Version 9.5 cf211
Version 9.5 cf212
Version 9.5 cf213
Version 9.5 cf214
Version 9.5 cf215
Version 9.5 cf216
Version 9.5 cf217
Version 9.5 cf218
Version 9.5 cf219
Version 9.5 cf220
Version 9.5 cf221
Version 9.5 cf222
Version 9.5 cf223
Version 9.5 cf224
Version 9.5 cf225
Version 9.5 cf226
Version 9.5 cf227
Version 9.5 cf228
Version 9.5 cf229
Version 9.5 cf230
Version 9.5 cf231
Version 9.5 cf232
Version 9.5 cf233
Version 9.5 cf234
Configuration B
12 vulnerable

Timeline

No history available yet.