CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs.  This only affects applications using the default login portlet.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-05 20:17

Updated : 2026-08-28 16:08


NVD link : CVE-2026-21766

Mitre link : CVE-2026-21766

CVE.ORG link : CVE-2026-21766


JSON object : View

Products Affected

No product.

CWE
CWE-522

Insufficiently Protected Credentials

CWE-532

Insertion of Sensitive Information into Log File