Executive brief
HCL Connections, a collaboration platform used for business networking and document sharing, is affected by a security flaw that allows users to bypass certain access restrictions. An authenticated user could potentially modify data they are not authorized to change, which could lead to unauthorized information updates or data integrity issues. This vulnerability requires a small amount of user interaction to be successfully exploited.
Technical details
HCL Connections is vulnerable to incorrect authorization (CWE-863) due to broken access controls. An authenticated attacker with low privileges can exploit this flaw over the network to modify data they should not have access to. The attack requires a low level of complexity but does necessitate some form of user interaction (UI:R). Successful exploitation allows the attacker to impact the integrity and confidentiality of the system's data, though it does not directly affect service availability. Users are advised to refer to HCL's security bulletin KB0129719 for remediation steps.
Affected products
- HCL Connections
Timeline
- 2026-05-18: advisory: Initial disclosure by HCL Software and NVD publication.