CVE-2026-21766

MEDIUM

HCL Digital Experience and Digital Experience Compose insufficiently protects credentials

Title source: cna
STIX 2.1

Description

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications using the default login portlet.

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522 CWE-532
Status published
Products (1)
HCLSoftware/HCL Digital Experience and Digital Experience Compose 9.5
Published Aug 05, 2026
Tracked Since Aug 06, 2026