Description
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
Published: 2026-08-26
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL Connections allows a server‑side request forgery (SSRF) that can be used when an attacker compromises an internal server or exploits certain vulnerable interfaces. The flaw can enable the attacker to instruct the Connections server to make unauthorized HTTP requests to internal or external resources, potentially leading to information disclosure or bypass of security controls. The weakness is classified as CWE‑918 and is represented by a CVSS score of 3.7, indicating low overall severity but non‑negligible impact if exploited in the right environment.

Affected Systems

This vulnerability affects the HCL Software Connections platform as identified by the CNA. No specific product versions are listed in the advisory, so all publicly available releases should be considered potentially affected until a vendor statement clarifies the scope.

Risk and Exploitability

The CVSS score of 3.7 reflects a low likelihood of successful exploitation in a general sense, yet the EPSS score is not available and the issue is not present in the CISA KEV catalog, suggesting that exploitation has not yet been observed in the wild. However, the SSRF vector is commonly leveraged by attackers to access hidden internal resources or to pivot to other systems. The likely attack path involves submitting crafted input that is processed by the Connections server to reach internal endpoints; if the server is already compromised, this flaw expands the attacker’s reach to sensitive data or privileged services.

Generated by OpenCVE AI on August 27, 2026 at 00:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any HCL Connections patch or upgrade that resolves the SSRF flaw; verify the fix on the HCL support site.
  • If a patch is unavailable, isolate the HCL Connections server from the internal network or restrict its outbound traffic to whitelisted IP addresses and ports only.
  • Implement strict input validation on all endpoints that form outbound requests, ensuring that only trusted URLs are reachable, to neutralize the effect of the SSRF vulnerability.

Generated by OpenCVE AI on August 27, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
Title HCL Connections is vulnerable to server-side request forgery (SSRF)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-26T22:24:39.177Z

Reserved: 2025-10-10T09:04:27.771Z

Link: CVE-2025-62341

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T23:17:10.317

Modified: 2026-08-26T23:17:10.317

Link: CVE-2025-62341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:30:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)