Description
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
Published: 2026-07-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL Commerce contains a privilege escalation flaw that can cause a denial of service, reveal personal user data, and let an attacker carry out unauthorized administrative tasks. The weakness is improper privilege management (CWE‑266), allowing an authenticated user to gain higher level rights without proper authorization.

Affected Systems

The vulnerability affects HCL Commerce from HCLSoftware. No version information is provided, so any deployment of HCL Commerce could be impacted. Administrators should verify the specific product version against the vendor’s advisory and apply any available fix.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker who already has valid user credentials exploiting the privilege escalation flaw to gain administrative privileges, which could enable denial of service and data disclosure. Although exploitation likelihood is low, the risk remains significant until a vendor patch is installed or other controls are in place.

Generated by OpenCVE AI on July 30, 2026 at 19:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the latest security patch for HCL Commerce as published by HCL Software in the vendor advisory linked above.
  • Review user accounts and enforce least‑privilege by removing any accidental administrative permissions.
  • Enable audit logging for privilege‑related actions and monitor logs for signs of unauthorized escalation or abnormal administrative activity.

Generated by OpenCVE AI on July 30, 2026 at 19:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech commerce
Vendors & Products Hcltech
Hcltech commerce

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
Title A privilege escalation vulnerability affects HCL Commerce
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hcltech Commerce
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-21T14:56:45.939Z

Reserved: 2026-01-05T16:08:22.254Z

Link: CVE-2026-21824

cve-icon Vulnrichment

Updated: 2026-07-21T13:39:26.315Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-20T16:16:56.777

Modified: 2026-07-21T17:09:21.500

Link: CVE-2026-21824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:30:09Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment