Executive brief
HCL Digital Experience, a platform used by organizations to build and manage digital customer experiences, contains a critical security flaw in its asset management component. An attacker could exploit this vulnerability to take full control of the underlying server, potentially leading to the theft of sensitive data or a complete shutdown of the service. This issue poses a significant risk to business operations and data integrity.
Technical details
An OS command injection vulnerability exists within the Digital Asset Management (DAM) API of HCL Digital Experience. The flaw allows a remote attacker to inject and execute arbitrary operating system commands by sending specially crafted requests to the affected API endpoint. Successful exploitation typically results in the attacker gaining the privileges of the application service account, which can lead to full system compromise, lateral movement, and unauthorized data access. Users are advised to consult HCL security bulletins for specific patch versions and remediation steps.
Affected products
- HCL Digital Experience
- HCL Digital Experience Compose
Timeline
- 2026-06-05: disclosed