Insufficient Credential Protection in HCL Digital Experience Login Portlet
CVE-2026-21766
5.4MEDIUM
What is CVE-2026-21766?
The default login portlet in HCL Digital Experience and HCL Digital Experience Compose has a significant security oversight that may compromise sensitive credential information. Under certain specific configurations and usage scenarios, credential data could inadvertently be recorded in web server logs, exposing sensitive information to unauthorized access. This vulnerability specifically affects applications utilizing the default login portlet, necessitating immediate attention and remediation to safeguard user credentials effectively.
Affected Version(s)
HCL Digital Experience and Digital Experience Compose 9.5
