CVE-2026-21766
Received Received - Intake

Default Login Portlet Credential Exposure in HCL Digital Experience

Vulnerability report for CVE-2026-21766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: HCL Software

Description

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Β Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.Β  This only affects applications using the default login portlet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-06
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hcl digital_experience *
hcl digital_experience_compose *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in HCL Digital Experience and Digital Experience Compose involves the default login portlet not properly protecting user credentials. Under very specific configurations, sensitive information may be logged by the web server.

Detection Guidance

Check HCL Digital Experience and Digital Experience Compose server logs for sensitive information related to login credentials. Look for entries containing plaintext passwords or authentication tokens in web server logs.

Impact Analysis

If exploited, this flaw could expose user credentials in web server logs, potentially leading to unauthorized access to accounts. The impact is limited to environments using the default login portlet with specific configurations.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR and HIPAA, which mandate strict controls over personal and health information.

Mitigation Strategies

Disable the default login portlet if not required. Review and update server log configurations to exclude sensitive credential data. Apply patches or updates from HCL as soon as they become available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21766. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart