AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-21766

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The default login portlet in HCL Digital Experience and Digital Experience Compose is vulnerable due to inadequate protection of credentials, which may lead to sensitive information being logged under specific configurations. Organizations utilizing the default login portlet should prioritize addressing this issue to mitigate the risk of credential exposure in web server logs. This vulnerability is particularly relevant for those managing applications that rely on this portlet for user authentication.

CVE
CVE-2026-21766
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%

Original NVD Description

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications using the default login portlet.