CVE-2026-21786
Low
|3.3No Exploit
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to access sensitive information, such as hostnames, that is unintentionally stored in the application logs and certain URLs of HCL Sametime for iOS. To exploit this, the attacker would need to gain access to these logs, which could happen if the device or application is not properly secured.
Technical Description
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
CVSS Vector Analysis
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$437($100-$500)
Vendor Response
Grade APatched in 4 days
Quick Information
Published
Mar 5, 2026
about 1 month ago
Last Modified
Mar 9, 2026
29 days ago
Vendor
hcltech
Product
sametime