Host Header Injection Vulnerability in HCL Digital Experience Products
CVE-2026-21826

6.1MEDIUM

What is CVE-2026-21826?

HCL Digital Experience and HCL Digital Experience Compose are prone to a Host header injection vulnerability. This flaw allows attackers to manipulate the Host header within requests, potentially resulting in the application's execution of unintended commands or exposure to other types of attacks. Organizations utilizing these products should assess their configurations and implement mitigative steps to safeguard against potential exploitation.

Affected Version(s)

Digital Experience & DX Compose 9.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.