CVE-2026-21754: HCL Hive is affected by multiple security vulnerabilities.
Published Aug 25, 2026
·Updated
HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.
Affected Software
1 affected component
HCL Hive
Event History
Aug 25, 2026
CVE Published
via MITRE·10:51 AM
Data Sourced
via MITRE·10:51 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit these issues?
The reported vector is network-based, requires low attack complexity, no privileges, and user interaction. The provided information does not identify the specific interaction required or the affected configurations.
2
What impact should defenders prioritize?
The reported impacts include unauthorized lateral movement, container breakout, and exposure of sensitive data in internal communications. The CVSS vector indicates low confidentiality and integrity impact, with no availability impact.