CVE-2026-56538
LOW
3.5
CVSS 3.1
Description
An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.
Metadata
Severity & Metrics
3.5
LOW CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| HCLSoftware | Connections | — | 8.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-213 | cna | CWE-213 Exposure of sensitive information due to incompatible policies |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 3.5 | LOW | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |