CVE-2026-21768

MEDIUM

HCL Verse for Android is susceptible to an injection vulnerability

Title source: cna
STIX 2.1

Description

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

Scores

CVSS v3 6.3
EPSS 0.0016
EPSS Percentile 5.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-79
Status published
Products (1)
HCLSoftware/Verse for Android 14.5.10
Published Jun 19, 2026
Tracked Since Jun 19, 2026