Description
HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.
Published: 2026-07-27
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL Connections has an information disclosure flaw that allows an attacker to read sensitive data they are not authorized to view. The root cause is improper handling of request data, which may expose confidential information. This weakness could enable attackers to obtain sensitive information, impacting confidentiality.

Affected Systems

This vulnerability affects HCL Connections from HCL Software. No specific version range is provided, so all deployments may be impacted until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 3.5 indicates low severity, and the EPSS score of < 1% (approximately 0.00156) and no KEV listing suggest a very low likelihood of exploitation. The attack vector appears to involve sending crafted requests to the application; if the service is publicly exposed, remote exploitation could be possible. Until a vendor fix is applied, the risk remains due to lack of mitigation.

Generated by OpenCVE AI on August 3, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether an update or patch is available from HCL Software by consulting official documentation or the support portal.
  • Restrict network access to the Connections service so that only trusted internal IP ranges can reach it, limiting exposure from the outside.
  • Implement strict input validation: reject or sanitize any request parameters that are not explicitly documented for the endpoint, preventing unintended data exposure.
  • Ensure application responses do not include sensitive data by verifying and removing any confidential attributes before sending data back to the requester.

Generated by OpenCVE AI on August 3, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech connections
Vendors & Products Hcltech
Hcltech connections

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.
Title HCL Connections is vulnerable to information disclosure
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Connections
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-27T15:44:23.507Z

Reserved: 2026-06-22T13:39:19.110Z

Link: CVE-2026-56537

cve-icon Vulnrichment

Updated: 2026-07-27T15:44:18.953Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-27T13:18:21.703

Modified: 2026-07-30T20:11:59.920

Link: CVE-2026-56537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information