Sensitive Information Disclosure in HCL Sametime for iOS
CVE-2026-21786

3.3LOW

Key Information:

Vendor
CVE Published:
5 March 2026

What is CVE-2026-21786?

HCL Sametime for iOS has been identified with a vulnerability that leads to sensitive information disclosure. This issue allows hostnames and certain URLs to be logged in the application logs, potentially exposing critical information. By leveraging this vulnerability, an attacker could obtain sensitive data that should remain confidential. It is crucial for users of HCL Sametime to review the application's logging practices and implement necessary security measures to safeguard sensitive information.

Affected Version(s)

Sametime for iOS < 12.0.26

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.