CVE-2025-68825 PUBLISHED

HCL Hive is affected by incorrect default permissions

Assigner: HCL
Reserved: 24.12.2025 Published: 24.08.2026 Updated: 24.08.2026

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 7.5

Product Status

Vendor HCLSoftware
Product HCL Hive
Versions Default: unaffected
  • Version 1.0 is affected

References

Problem Types

  • CWE-276 Incorrect default permissions CWE