Back to overview

CVE-2026-56538

LOW
3.5
CVSS 3.1
Description
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

Metadata

CVE ID
CVE-2026-56538
State
PUBLISHED
Assigner
HCL
Reserved
2026-06-22 13:39 UTC
Published
2026-07-27 11:55 UTC
Last updated
2026-07-27 15:43 UTC
Primary CWE
CWE-213
CWE-213 Exposure of sensitive information due to incompatibl…
Vendor / Product
HCLSoftware / Connections
Sources
cve.org  ·  NVD

Severity & Metrics

3.5 LOW CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
HCLSoftware Connections 8.0
Weakness (CWE)
CWESourceDescription
CWE-213 cna CWE-213 Exposure of sensitive information due to incompatible policies
CVSS scores (1)
ScoreSeverityVersionSourceVector
3.5 LOW 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Back to overview