CVE-2026-21827: Low severity vulnerability
Published Aug 31, 2026
·Updated
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.
Event History
Aug 31, 2026
CVE Published
via NVD·04:17 PM
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account or elevated privileges?
No privileges are required according to the CVSS vector. The attack is network-reachable, but it has high attack complexity and requires user interaction.
2
What is the expected security impact if exploitation succeeds?
The reported impact is limited to confidentiality, with low confidentiality impact. No integrity or availability impact is indicated.