CVE-2026-21786: HCL Sametime for iOS is affected by sensitive information disclosure
Published Mar 5, 2026
·Updated
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
Affected Software
2 affected components
HCL Sametime for iOS
hcltech Sametime Iphone Os<12.0.26
Event History
Mar 5, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21786?
CVE-2026-21786 is rated as a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2026-21786?
To mitigate CVE-2026-21786, ensure that application logging is configured to not include sensitive information such as hostnames and URLs.
3
What information is disclosed in CVE-2026-21786?
CVE-2026-21786 allows for the disclosure of sensitive information including hostnames and certain URLs in application logs.
4
Which software versions are affected by CVE-2026-21786?
CVE-2026-21786 specifically affects HCL Sametime for iOS.
5
Is CVE-2026-21786 easy to exploit?
CVE-2026-21786 may not require sophisticated techniques to exploit, making it important to address promptly.