← Vulnerability feed

Vulnerability record · CVE-2026-21837 · published 5 June 2026

CVE-2026-21837: Hcltech digital experience os command injection vulnerability

Hcltech · Digital Experience

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

8.7 CVSS 4.0 High EPSS 0.92% · top 41.3% CWE-78 · OS command injection
8.7CVSS 4.0 base score
0.92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21837 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-14255Hcltech digital experience vulnerabilityHCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These af…EPSS 1.1%6.1CVE-2026-21825Hcltech digital experience compose cross-site scripting vulnerabilityHCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute a…EPSS 0.15%6.1CVE-2026-21826Hcltech digital experience compose open redirect vulnerabilityHCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header …EPSS 0.14%6.1CVE-2023-37538Hcltech digital experience cross-site scripting vulnerabilityHCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker m…EPSS 0.36%6.1CVE-2020-4081Hcltech digital experience cross-site scripting vulnerabilityIn Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS).EPSS 0.63%6.1CVE-2020-14223Hcltech digital experience cross-site scripting vulnerabilityHCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persiste…EPSS 0.64%5.4CVE-2022-38653Hcltech digital experience cross-site scripting vulnerabilityIn HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.EPSS 0.30%4.9CVE-2020-14221Hcltech digital experience vulnerabilityHCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2026-21837), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.