CVE-2026-21768
Received Received - Intake
Cross-Site Scripting in HCL Verse for Android

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: HCL Software

Description
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-19
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hcl verse_for_android 1.0.0_rc14
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in the compose-rich-editor library (version 1.0.0-rc14) used by HCL Verse for Android for composing rich text emails. It fails to properly validate all HTML input, which allows malicious content to be executed in certain situations.

Impact Analysis

This vulnerability can lead to the execution of malicious content when composing emails, potentially allowing an attacker to compromise the confidentiality and integrity of your email communications. The CVSS score indicates a high impact on confidentiality and integrity, though availability is not affected.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart