Description
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications using the default login portlet.
Published: 2026-08-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A default login portlet in HCL Digital Experience and Digital Experience Compose fails to adequately protect credentials. In certain specific configurations, the portlet writes sensitive information to web server logs. This can expose usernames, passwords, or other authentication data to anyone with access to these log files, compromising confidentiality and potentially allowing further compromise.

Affected Systems

The vulnerability affects installations of HCL Digital Experience and Digital Experience Compose that use the default login portlet. No specific product versions are listed, but it applies to any configuration that enables the portlet’s default behavior of logging credential data to the web server.

Risk and Exploitability

The CVSS score of 5.4 indicates medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or undocumented exploitation. The likely attack vector involves interacting with the insecure login portlet, triggering the use of the portlet’s default logging behavior. If an attacker can view or obtain the web server’s log files, credential data may be retrieved. The medium CVSS score and absence of known exploits imply that the risk is moderate but could be serious if effective log access is achieved.

Generated by OpenCVE AI on August 5, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued fix for the credential logging issue as described in HCL’s support article KB0132659.
  • If an immediate update is not possible, disable the default login portlet or reconfigure it so that it does not write authentication details to the web server logs.
  • Ensure web server log settings suppress or mask sensitive authentication data, and restrict log file access to authorized personnel only.

Generated by OpenCVE AI on August 5, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications using the default login portlet.
Title HCL Digital Experience and Digital Experience Compose insufficiently protects credentials
Weaknesses CWE-522
CWE-532
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-05T20:11:19.443Z

Reserved: 2026-01-05T16:07:58.367Z

Link: CVE-2026-21766

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T21:45:04Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials

  • CWE-532

    Insertion of Sensitive Information into Log File