What is CVE-2026-21766?
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under specific configurations and use cases, sensitive information may be written to web server logs. This affects only applications using the default login portlet; immediate configuration review and log sanitization is recommended.
Azərbaycanca: HCL Digital Experience və Digital Experience Compose proqramlarında standart giriş portleti etimadnamələri kifayət qədər qorumur. Müəyyən spesifik konfiqurasiya və istifadə hallarında həssas məlumatlar veb server jurnallarına yazıla bilər. Yalnız standart giriş portletindən istifadə edən tətbiqlər təsirlənir; dərhal konfiqurasiyanı yoxlamaq və həssas məlumatların jurnallardan təmizlənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: HCL
FAQ2
Which HCL products are affected by CVE-2026-21766?
HCL Digital Experience and Digital Experience Compose are affected, but only applications that use the default login portlet are vulnerable to this weakness.
What happens when CVE-2026-21766 is exploited?
Under specific configurations and use cases, sensitive information such as credentials may be written to web server logs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.