CVE-2026-56538CWE-213

CVE-2026-56538

Low · published July 27, 2026

CVSS v3.1
3.5
EPSS
0%
Percentile
5.4
In the wild
Unconfirmed
What it is

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

The record
Technical detail
CVSS v3.1
3.5 · LOW
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00159 · 5.4th percentile
Weakness
CWE-213 · Exposure of Sensitive Information Due to Incompatible Policies
Published
2026-07-27T17:18Z
Affected products (12)
ProductVersionsFixed in
hcltech/connections< 8.08.0
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
hcltech/connectionsall versions
References (1)
EPSS history
Timeline
  • 27 JUL 11:55Z
    HCL Connections is vulnerable to information disclosure
    cvelistv5