Disclosure summary
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
Source-reported weakness categories
CWE-209, CWE-434
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-59872
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| hcltech | zie_for_web | 16.0 |
Original records & references
- NIST NVD record
- CVE Program record
- support.hcl-software.com — Vendor Advisory
PUBLISHED 2026-06-17T09:19:15-04:00
MODIFIED 2026-10-06T18:10:00-04:00
INGESTED 2026-10-10T20:25:11-04:00