Description
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
Published: 2026-07-27
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An endpoint in HCL Connections is vulnerable to information disclosure, meaning that unauthorized users may be able to retrieve sensitive data from the system. The weakness is classified as CWE‑213, which involves insufficient protection of information the result of an unintended exposure. The impact is the leakage of confidential data that could compromise the privacy and integrity of users monitored by the service.

Affected Systems

The vulnerability affects the HCLSoftware Connections product. No specific version details are indicated in the advisory, so all deployed instances of this application may be at risk until a patch or update is released by the vendor.

Risk and Exploitability

The CVSS score of 3.5 indicates a low severity, and the EPSS score is below 1%, translating to a very low probability of exploitation. The flaw is not listed in CISA's KEV catalog, further suggesting it is unlikely to be actively exploited. The attack vector is inferred to be remote access to the vulnerable endpoint; an attacker must send crafted requests to the endpoint to cause the information disclosure. No public exploit or detailed attack path is documented in the available information.

Generated by OpenCVE AI on August 3, 2026 at 17:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify if HCL Software has released a patch for the disclosure flaw in the Connections application; apply the patch as soon as it becomes available.
  • If no patch exists, restrict network access to the affected endpoint using firewall rules or access controls, limiting traffic to trusted users only.
  • Monitor application and network logs for anomalous activity that may indicate attempts to retrieve sensitive data from the exposed endpoint.

Generated by OpenCVE AI on August 3, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech connections
Vendors & Products Hcltech
Hcltech connections

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
Title HCL Connections is vulnerable to information disclosure
Weaknesses CWE-213
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Connections
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-27T15:43:39.605Z

Reserved: 2026-06-22T13:39:19.110Z

Link: CVE-2026-56538

cve-icon Vulnrichment

Updated: 2026-07-27T15:43:35.384Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-27T13:18:21.827

Modified: 2026-07-30T20:11:59.920

Link: CVE-2026-56538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-213

    Exposure of Sensitive Information Due to Incompatible Policies