CVE-2026-21755: HCL Hive is affected by a missing rate limit
Published Aug 24, 2026
·Updated
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.
Affected Software
1 affected component
HCL HCL Hive
Event History
Aug 24, 2026
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker can attempt brute-force or credential-stuffing attacks remotely without authentication or user interaction. The issue may also be abused to cause a denial of service.
2
What security impact should be prioritized?
The stated impact is unauthorized access through successful credential attacks and possible denial of service. The CVSS vector indicates integrity impact is limited, with no stated confidentiality or availability impact in the score.