Description
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.
Published: 2026-08-31
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from HCL Connections improperly processing request data that users do not have permission to access. This flaw allows an attacker to read sensitive information that should be restricted, resulting in an information disclosure scenario. The weakness is classified under CWE‑359, indicating insufficient verification of data authenticity.

Affected Systems

Affected systems are deployments of HCL Connections from HCLSoftware. The specific version range that is vulnerable is not listed in the advisory, so any installation running an unpatched or older version may be impacted. Administrators should verify their installation version against the vendor’s support page for a patch or newer release.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall risk, and there is no evidence that exploitation is currently in use or listed in CISA KEV catalog. The EPSS score is not available, so the probability of exploitation is unknown. Because the advisory does not specify an attack vector, the likely path would involve a user submitting a request that includes unauthorized data; the flaw is exploitable only if the system allows such request processing. In the absence of exploitation evidence, the threat is low but should still be addressed promptly to prevent accidental disclosure.

Generated by OpenCVE AI on August 31, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install the latest vendor patch or upgrade HCL Connections to the most recent supported version.
  • Verify that access controls and authentication checks are enforced so that request data is only processed for authorized users; review the application's configuration for any mis‑configured permissions.
  • Monitor system and audit logs for any anomalous requests or attempts to access restricted data, and remediate findings immediately.

Generated by OpenCVE AI on August 31, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.
Title HCL Connections is vulnerable to an information disclosure vulnerability
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-31T15:48:17.026Z

Reserved: 2026-01-05T16:08:22.255Z

Link: CVE-2026-21827

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T16:17:55.830

Modified: 2026-08-31T16:17:55.830

Link: CVE-2026-21827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T17:30:03Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor