CVE-2026-21827
Received Received - Intake

Information Disclosure in HCL Connections

Vulnerability report for CVE-2026-21827, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: HCL Software

Description

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl connections *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-359 The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL Connections has an information disclosure vulnerability where improper handling of request data allows users to access sensitive information they are not authorized to see.

Impact Analysis

An attacker could exploit this to view confidential data, potentially leading to data breaches or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized data exposure, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Apply the security update provided by HCL Connections as soon as possible to address the improper handling of request data that leads to information disclosure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21827. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart