CVE-2026-21766
Received
Received - Intake
Default Login Portlet Credential Exposure in HCL Digital Experience
Vulnerability report for CVE-2026-21766, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-05
Last updated on: 2026-08-05
Assigner: HCL Software
Description
Description
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Β Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.Β This only affects applications using the default login portlet.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcl | digital_experience | * |
| hcl | digital_experience_compose | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |