Junglewise Threat Intelligence

CVE-2026-21789: HCL Connections broken access control vulnerability

CVE-2026-21789 · Severity: medium · CVSS 4.6 · Published 2026-05-18

Vendors: HCL.

Executive brief

HCL Connections, a collaboration platform used for business networking and document sharing, is affected by a security flaw that allows users to bypass certain access restrictions. An authenticated user could potentially modify data they are not authorized to change, which could lead to unauthorized information updates or data integrity issues. This vulnerability requires a small amount of user interaction to be successfully exploited.

Technical details

HCL Connections is vulnerable to incorrect authorization (CWE-863) due to broken access controls. An authenticated attacker with low privileges can exploit this flaw over the network to modify data they should not have access to. The attack requires a low level of complexity but does necessitate some form of user interaction (UI:R). Successful exploitation allows the attacker to impact the integrity and confidentiality of the system's data, though it does not directly affect service availability. Users are advised to refer to HCL's security bulletin KB0129719 for remediation steps.

Affected products

  • HCL Connections

Timeline

  • 2026-05-18: advisory: Initial disclosure by HCL Software and NVD publication.

References