CVE-2025-62341: HCL Connections is vulnerable to server-side request forgery (SSRF)
Published Aug 26, 2026
·Updated
HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain scenarios leading to information disclosure or security bypass.
Affected Software
1 affected component
HCL Connections
Event History
Aug 26, 2026
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and conditions are required for exploitation?
The issue requires an attacker to have low-privileged access and user interaction. Exploitation is also rated as high complexity and is described as occurring when an internal server is compromised.
2
What could an attacker achieve if exploitation succeeds?
An attacker may be able to send unauthorized requests in certain scenarios. The stated impacts are information disclosure or a security bypass, with low confidentiality and integrity impact and no availability impact.