CVE-2026-21789: HCL Connections is vulnerable to broken access control
Published May 18, 2026
·Updated
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
Affected Software
1 affected component
HCL HCL Connections
Event History
May 18, 2026
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-21789?
The severity of CVE-2026-21789 is high due to its potential to allow unauthorized data modification.
2
How do I fix CVE-2026-21789?
To fix CVE-2026-21789, update HCL Connections to the latest version that addresses the broken access control vulnerability.
3
What scenarios are affected by CVE-2026-21789?
CVE-2026-21789 affects scenarios where improper access controls allow unauthorized users to update sensitive data.
4
Who is impacted by CVE-2026-21789?
Organizations using HCL Connections with insufficient access controls are impacted by CVE-2026-21789.
5
Can CVE-2026-21789 lead to data breaches?
Yes, CVE-2026-21789 can potentially lead to data breaches if unauthorized users exploit the vulnerability.