CVE-2026-21837
HIGHHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API
Title source: cnaDescription
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
References (1)
Core 1
Scores
CVSS v3
8.8
EPSS
0.0092
EPSS Percentile
55.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
HCLSoftware/Digital Experience
9.5
hcltech/digital_experience
9.5 (49 CPE variants)
Published
Jun 05, 2026
Tracked Since
Jun 05, 2026