๐Ÿ” CVE Alert

CVE-2026-21768

MEDIUM 6.3

HCL Verse for Android is susceptible to an injection vulnerability

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed in certain situations.

CWE CWE-20 CWE-79
Vendor hclsoftware
Product verse for android
Published Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for hclsoftware verse for android

Be the first to know when new medium vulnerabilities affecting hclsoftware verse for android are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

HCLSoftware / Verse for Android
14.5.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.hcl-software.com: https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130866