CVE-2026-56538: HCL Connections is vulnerable to information disclosure
Published Jul 27, 2026
·Updated
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
Affected Software
13 affected components
HCL HCL Connections
hcltech Connections<8.0
hcltech Connections=8.0
hcltech Connections=8.0-cumulative_release1
hcltech Connections=8.0-cumulative_release10
hcltech Connections=8.0-cumulative_release2
hcltech Connections=8.0-cumulative_release3
hcltech Connections=8.0-cumulative_release4
hcltech Connections=8.0-cumulative_release5
hcltech Connections=8.0-cumulative_release6
hcltech Connections=8.0-cumulative_release7
hcltech Connections=8.0-cumulative_release8
hcltech Connections=8.0-cumulative_release9
Remediation
Event History
Jul 27, 2026
CVE Published
via MITRE·11:55 AM
Data Sourced
via MITRE·11:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-56538?
The severity of CVE-2026-56538 is classified as low with a score of 3.5.
2
What type of vulnerability is CVE-2026-56538?
CVE-2026-56538 is an information disclosure vulnerability in HCL Connections.
3
Who is affected by CVE-2026-56538?
Users of HCL Connections may be affected if sensitive information is exposed to unauthorized users.
4
How do I fix CVE-2026-56538?
To fix CVE-2026-56538, it is recommended to apply any available patches or updates provided by HCL Software.
5
What impact does CVE-2026-56538 have?
CVE-2026-56538 may lead to the disclosure of sensitive information, which could compromise user privacy.