Insufficient Credential Protection in HCL Digital Experience Login Portlet
CVE-2026-21766

5.4MEDIUM

What is CVE-2026-21766?

The default login portlet in HCL Digital Experience and HCL Digital Experience Compose has a significant security oversight that may compromise sensitive credential information. Under certain specific configurations and usage scenarios, credential data could inadvertently be recorded in web server logs, exposing sensitive information to unauthorized access. This vulnerability specifically affects applications utilizing the default login portlet, necessitating immediate attention and remediation to safeguard user credentials effectively.

Affected Version(s)

HCL Digital Experience and Digital Experience Compose 9.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.