CVE-2025-31966: Hcltech Sametime

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL Sametime is vulnerable to broken server-side validation. While the application performs client-side input checks, these are not enforced by the web server. An attacker can bypass these restrictions by sending manipulated HTTP requests directly to the server.

Affected products

  • Hcltech Sametime: before 12.0.3 (fixed in 12.0.3)

Published 2026-03-17. Last modified 2026-06-17.