CVE-2026-21827 PUBLISHED

HCL Connections is vulnerable to an information disclosure vulnerability

Assigner: HCL
Reserved: 05.01.2026 Published: 31.08.2026 Updated: 31.08.2026

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 3.1

Product Status

Vendor HCLSoftware
Product Connections
Versions Default: unaffected
  • Version 7.0, 8.0 is affected

References

Problem Types

  • CWE-359 Exposure of private personal information to an unauthorized actor CWE