CVE-2026-21756 PUBLISHED

HCL Hive is affected by a broken access control vulnerability

Assigner: HCL
Reserved: 05.01.2026 Published: 24.08.2026 Updated: 24.08.2026

HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor HCLSoftware
Product HCL Hive
Versions Default: unaffected
  • Version 1.0 is affected

References

Problem Types

  • CWE-266 Incorrect privilege assignment CWE