HCLTech GRAGON Arbitrary Code Execution Vulnerability via Unrestricted API Request Handling
Vulnerability
A vulnerability allowing remote code execution exists in HCLTech GRAGON versions prior to 7.6.0. This issue arises because certain APIs do not impose restrictions on the quantity or size of requests, enabling potential exploitation.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the server where HCLTech GRAGON is running.
Added: Dec 3, 2025, 7:19 PM
Updated: Dec 3, 2025, 7:19 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
7.4remediation
0.0relevance
1.3threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
