Junglewise Threat Intelligence

CVE-2025-62299: HCL IntelliOps Event Management privilege escalation

CVE-2025-62299 · Severity: medium · CVSS 6.6 · Published 2026-08-20

Vendors: HCL.

Executive brief

HCL IntelliOps Event Management (IEM) is a platform for event management and operations monitoring. A privilege escalation vulnerability allows attackers to access resources and perform actions with elevated permissions that should not be available to their user account, potentially leading to unauthorized data access or system manipulation.

Technical details

The vulnerability is a privilege escalation (least privileges violation) in HCL IntelliOps Event Management. An authenticated attacker can bypass privilege restrictions to access resources or functionality normally restricted to higher-privilege users. The exact attack mechanism and vulnerable component details are not fully disclosed, but the flaw allows privilege escalation from a lower-privilege account to gain unauthorized elevated access. A patch or mitigation guidance may be available from HCL support.

Affected products

  • HCL IntelliOps Event Management

Timeline

  • 2026-08-20: disclosed

References