Junglewise Threat Intelligence

CVE-2026-21824: HCL Commerce privilege escalation via incorrect privilege assignment

CVE-2026-21824 · Severity: high · CVSS 8.8 · Published 2026-07-20

Vendors: HCL Software.

Executive brief

HCL Commerce, a platform used by businesses to manage online storefronts and digital sales, is affected by a security flaw that allows users with low-level access to gain unauthorized administrative control. An attacker could exploit this to steal sensitive customer data, disrupt the website's availability, or perform unauthorized business operations. This poses a significant risk to both operational continuity and the protection of personal consumer information.

Technical details

A privilege escalation vulnerability exists in HCL Commerce due to incorrect privilege assignment (CWE-266). The flaw allows a remote authenticated attacker with low-level privileges to elevate their permissions to an administrative level. By exploiting this vulnerability, an attacker can gain full control over the commerce environment, leading to the unauthorized disclosure of sensitive user data, execution of administrative tasks, or a complete denial of service. The vulnerability affects versions 7, 8.x, and specific releases within the 9.0 and 9.1 branches. Users are advised to consult HCL security bulletin KB0130114 for patching information.

Affected products

  • HCL Software Commerce 7, 8.x, 9.0 - 9.0.1.21, 9.1.0 - 9.1.19

Timeline

  • 2026-07-20: advisory
  • 2026-07-20: disclosed

References