CVE-2026-21837

HIGH

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API

Title source: cna
STIX 2.1

Description

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

Scores

CVSS v3 8.8
EPSS 0.0092
EPSS Percentile 55.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
HCLSoftware/Digital Experience 9.5
hcltech/digital_experience 9.5 (49 CPE variants)
Published Jun 05, 2026
Tracked Since Jun 05, 2026