HTML Input Validation Flaw in HCL Verse for Android Rich Text Email Composition
CVE-2026-21768

6.3MEDIUM

Key Information:

Vendor
CVE Published:
19 June 2026

What is CVE-2026-21768?

The compose-rich-editor library in HCL Verse for Android's rich text email composition does not adequately validate HTML inputs. This oversight can permit the execution of harmful scripts in specific scenarios, potentially jeopardizing the security of users' devices and email data.

Affected Version(s)

Verse for Android 14.5.10

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.