OS Command Injection Vulnerability in HCL Digital Experience
CVE-2026-21837
8.7HIGH
What is CVE-2026-21837?
HCL Digital Experience contains an OS command injection vulnerability within the Digital Asset Management API. This flaw allows an attacker to execute arbitrary operating system commands by exploiting the API, typically running with the privileges of the affected application. This could enable unauthorized access to system resources and pose significant risks, including potential data breaches and system compromise.
Affected Version(s)
Digital Experience 9.5
