Executive brief
HCL Connections is a collaborative workplace platform used by organizations to manage team communication and content sharing. An information disclosure vulnerability could allow users to access sensitive information they should not have permission to view, due to improper request data handling.
Technical details
This vulnerability is an information disclosure flaw in HCL Connections caused by improper handling of request data. The vulnerability allows an authenticated user to bypass access controls and obtain sensitive information they are not entitled to access. The attack requires valid user credentials and network access to the HCL Connections service. An attacker would need to craft malicious requests to exploit the improper data handling. No evidence of active exploitation in the wild has been reported. Patches or updates addressing this issue should be available from HCL support.
Affected products
- HCL Connections
Timeline
- 2026-08-31: disclosed