Executive brief
HCL Digital Experience Compose, a platform used for building and managing digital content and web experiences, contains a security flaw in its search center component. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of sensitive session information or the unauthorized performance of actions on behalf of the user.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the search center component of HCL Digital Experience Compose. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by persuading a user to visit a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript code in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access. The vulnerability is tracked as CVE-2026-21825 and has been assigned a CVSS v3.1 base score of 6.1.
Affected products
- HCL Digital Experience Compose
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory