HCL Commerce Privilege Escalation Vulnerability Allowing Denial-of-Service and Unauthorized Data Access

Vulnerability

A privilege escalation vulnerability has been identified in HCL Commerce that could lead to denial-of-service, unauthorized access to user personal data, and the execution of unauthorized administrative tasks. This vulnerability affects multiple versions of HCL Commerce, including WebSphere Commerce version 7, WebSphere Commerce versions 8.x, HCL Commerce versions 9.0 - 9.0.1.21, HCL Commerce versions 9.1.0 - 9.1.19, and HCL Commerce Plus Transaction Server up to version 25.09.17.

Impact

Exploitation of this vulnerability could result in unauthorized administrative actions, denial-of-service conditions, and unauthorized access to personal user data.

Remediation

Users can apply the HCL Commerce Security Fix KB0130114. For HCL Commerce versions 9.1.0 - 9.1.19, upgrading to version 9.1.20.0 or higher is recommended. HCL Commerce releases and fix packs can be downloaded from My HCLSoftware - Commerce.

Added: Jul 20, 2026, 5:20 PM
Updated: Jul 20, 2026, 5:20 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
7.5
exploitability
5.4
remediation
7.7
relevance
10.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.