Junglewise Threat Intelligence

CVE-2025-62341: HCL Connections server-side request forgery

CVE-2025-62341 · Severity: low · CVSS 3.7 · Published 2026-08-26

Vendors: HCL.

Executive brief

HCL Connections is a collaboration and communication platform used to manage enterprise content and social workflows. When an internal server is compromised, an attacker can exploit a server-side request forgery (SSRF) vulnerability to send unauthorized requests, potentially leading to information disclosure or security bypass within the internal network.

Technical details

The vulnerability is a server-side request forgery (SSRF) issue in HCL Connections that manifests when an internal server within the deployment has been compromised by an attacker. The flaw allows the attacker to craft and send unauthorized requests to other internal systems or resources, bypassing access controls. This vulnerability requires prior compromise of an internal server as a precondition. Exploitation can lead to information disclosure from internal services or security bypasses that depend on network isolation. Patch availability and specific affected versions should be confirmed via HCL support channels.

Affected products

  • HCL Connections

Timeline

  • 2026-08-26: disclosed

References