CVE-2026-21826
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
8th
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
| CWE | CWE-601 |
| Vendor | hclsoftware |
| Product | digital experience & dx compose |
| Published | Jun 5, 2026 |
| Last Updated | Jun 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for hclsoftware digital experience & dx compose
Be the first to know when new medium vulnerabilities affecting hclsoftware digital experience & dx compose are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
HCLSoftware / Digital Experience & DX Compose
9.5