Junglewise Threat Intelligence

CVE-2026-21826: HCL Digital Experience Host header injection

CVE-2026-21826 · Severity: medium · CVSS 6.1 · Published 2026-06-05

Technologies: HCL Digital Experience Compose. Vendors: HCL.

Executive brief

HCL Digital Experience, a platform used for building and managing digital content and customer portals, is vulnerable to a security flaw where an attacker can manipulate web request headers. This could allow an attacker to redirect users to malicious websites or cause the application to behave unexpectedly. Such an exploit could be used in phishing campaigns to steal user credentials or damage the organization's reputation by misusing the trusted domain.

Technical details

HCL Digital Experience and HCL Digital Experience Compose are vulnerable to Host header injection (CWE-601). The vulnerability arises because the application fails to properly validate the 'Host' header in incoming HTTP requests. A remote, unauthenticated attacker can exploit this by sending a specially crafted request with a manipulated Host header. If successful, this can lead to Open Redirection, where a user is redirected to an untrusted external site, or other unexpected application behaviors. Exploitation requires some level of user interaction (UI:R). HCL has released a security bulletin (KB0130849) addressing this issue.

Affected products

  • HCL Digital Experience
  • HCL Digital Experience Compose

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats