CVE-2026-21824

Summary

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareCommerce7, 8.x, 9.0 - 9.0.1.21, 9.1.0 - 9.1.19,affected

Weaknesses

  • CWE-266: CWE-266 Incorrect privilege assignment

References