Executive brief
HCL Digital Experience, a platform used for building and managing digital content and customer portals, is vulnerable to a security flaw where an attacker can manipulate web request headers. This could allow an attacker to redirect users to malicious websites or cause the application to behave unexpectedly. Such an exploit could be used in phishing campaigns to steal user credentials or damage the organization's reputation by misusing the trusted domain.
Technical details
HCL Digital Experience and HCL Digital Experience Compose are vulnerable to Host header injection (CWE-601). The vulnerability arises because the application fails to properly validate the 'Host' header in incoming HTTP requests. A remote, unauthenticated attacker can exploit this by sending a specially crafted request with a manipulated Host header. If successful, this can lead to Open Redirection, where a user is redirected to an untrusted external site, or other unexpected application behaviors. Exploitation requires some level of user interaction (UI:R). HCL has released a security bulletin (KB0130849) addressing this issue.
Affected products
- HCL Digital Experience
- HCL Digital Experience Compose
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory