CVE-2026-21788 PUBLISHED

HCL Connections is vulnerable to cross-site scripting (XSS)

Assigner: HCL
Reserved: 05.01.2026 Published: 19.03.2026 Updated: 19.03.2026

HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code.  This may allow the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor HCLSoftware
Product Connections
Versions Default: unaffected
  • Version 8 is affected

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE