← Back

CVE-2026-21826

nvd nist
Published: Jun 5, 2026Modified: Jun 10, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: psirt@hcl.com (Secondary)

Description

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

Affected (67)

2 products
Digital Experience Compose
Digital Experience
Configuration A
12 vulnerable
Configuration B
55 vulnerable
Vulnerable SoftwareAffected Versions
Hcltech
Version 9.5
Version 9.5 cf171
Version 9.5 cf172
Version 9.5 cf173
Version 9.5 cf17
Version 9.5 cf181
Version 9.5 cf182
Version 9.5 cf183
Version 9.5 cf184
Version 9.5 cf18
Version 9.5 cf191
Version 9.5 cf192
Version 9.5 cf193
Version 9.5 cf194
Version 9.5 cf195
Version 9.5 cf196
Version 9.5 cf197
Version 9.5 cf198
Version 9.5 cf199
Version 9.5 cf19
Version 9.5 cf200
Version 9.5 cf201
Version 9.5 cf202
Version 9.5 cf203
Version 9.5 cf204
Version 9.5 cf205
Version 9.5 cf206
Version 9.5 cf207
Version 9.5 cf208
Version 9.5 cf209
Version 9.5 cf210
Version 9.5 cf211
Version 9.5 cf212
Version 9.5 cf213
Version 9.5 cf214
Version 9.5 cf215
Version 9.5 cf216
Version 9.5 cf217
Version 9.5 cf218
Version 9.5 cf219
Version 9.5 cf220
Version 9.5 cf221
Version 9.5 cf222
Version 9.5 cf223
Version 9.5 cf224
Version 9.5 cf225
Version 9.5 cf226
Version 9.5 cf227
Version 9.5 cf228
Version 9.5 cf229
Version 9.5 cf230
Version 9.5 cf231
Version 9.5 cf232
Version 9.5 cf233
Version 9.5 cf234

Timeline

No history available yet.