CVE-2026-21824
HIGH
8.8
CVSS 3.1
Description
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
Metadata
Severity & Metrics
8.8
HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| HCLSoftware | Commerce | — | 7, 8.x, 9.0 - 9.0.1.21, 9.1.0 - 9.1.19, |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-266 | cna | CWE-266 Incorrect privilege assignment |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 8.8 | HIGH | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |