HCLTech GRAGON Arbitrary Code Execution Vulnerability via Unrestricted API Request Handling

Vulnerability

A vulnerability allowing remote code execution exists in HCLTech GRAGON versions prior to 7.6.0. This issue arises because certain APIs do not impose restrictions on the quantity or size of requests, enabling potential exploitation.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where HCLTech GRAGON is running.

Added: Dec 3, 2025, 7:19 PM
Updated: Dec 3, 2025, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
1.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.