CVE-2025-55261Disclosure(hcltech / aftermarket_cloud)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aftermarket_cloud

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
aftermarket_cloud

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 103-2603-29
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-55261 HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and… https://www.cve.org/CVERecord?id=CVE-2025-55261

    Post summary

    The tweet announces CVE-2025-55261, noting that HCL Aftermarket DPC lacks functional level access control, allowing privilege escalation.

    00000170
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-55261 - High HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate... https://www.thehackerwire.com/vulnerability/CVE-2025-55261/ https://t.co/VWCNDcIbEh

    Post summary

    High‑severity CVE‑2025‑55261 in HCL Aftermarket DPC is disclosed, highlighting a missing functional level access control that could enable privilege escalation and data theft.

    00000157
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphcltechaftermarket_cloud1.0.0--

Explore more