CVE-2026-21827CWE-359

CVE-2026-21827

Low · published August 31, 2026

CVSS v3.1
3.1
EPSS
0%
Percentile
4.6
In the wild
Unconfirmed
What it is

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data.

The record
Technical detail
CVSS v3.1
3.1 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00151 · 4.6th percentile
Weakness
CWE-359 · Exposure of Private Personal Information to an Unauthorized Actor
Published
2026-08-31T20:17Z
References (1)
EPSS history
Timeline
  • 02 SEP 03:34Z
    EPSS moved — → 0%
    epss
  • 31 AUG 15:48Z
    HCL Connections is vulnerable to an information disclosure vulnerability
    cvelistv5