CVE-2026-56537 PUBLISHED

HCL Connections is vulnerable to information disclosure

Assigner: HCL
Reserved: 22.06.2026 Published: 27.07.2026 Updated: 27.07.2026

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 3.5

Product Status

Vendor HCLSoftware
Product Connections
Versions Default: unaffected
  • Version 8.0 is affected

References

Problem Types

  • CWE-209 Generation of error message containing sensitive information CWE