CVE-2025-68825: HCL Hive is affected by incorrect default permissions
Published Aug 24, 2026
·Updated
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.
Affected Software
1 affected component
HCL Hive
Event History
Aug 24, 2026
CVE Published
via MITRE·03:37 PM
Data Sourced
via MITRE·03:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is rated AV:N/AC:L/PR:N/UI:N, indicating it can be exploited over the network with low attack complexity, without prior privileges, and without user interaction.
2
What could an attacker do after exploiting the issue?
The reported impacts include unauthorized lateral movement, container breakout, and interception of sensitive internal communications. The CVSS vector indicates high confidentiality impact, with no stated integrity or availability impact.