Junglewise Threat Intelligence

CVE-2025-15619: HCL Connections broken access control

CVE-2025-15619 · Severity: low · CVSS 3.5 · Published 2026-06-23

Vendors: HCL Software.

Executive brief

HCL Connections, a collaboration platform for businesses, contains a security flaw that could allow an unauthorized user to view certain data. This issue occurs in a specific, limited scenario and requires a user to be logged into the system to exploit it. While the risk is considered low, it could lead to the unintended disclosure of internal information.

Technical details

HCL Connections versions 7.0 and 8.0 are affected by a broken access control vulnerability (CWE-284) and cleartext transmission of sensitive information (CWE-319). The flaw allows a remote authenticated attacker with low privileges to bypass access restrictions and view data in a specific scenario, provided there is some level of user interaction. The vulnerability is rated as low severity with a CVSS score of 3.5, primarily impacting confidentiality. Users are advised to refer to HCL Software's security bulletin KB0130163 for remediation steps.

Affected products

  • HCL Software Connections 7.0, 8.0

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory

References