CVE-2026-21756: HCL Hive is affected by a broken access control vulnerability
Published Aug 24, 2026
·Updated
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
Affected Software
1 affected component
HCL Hive
Event History
Aug 24, 2026
CVE Published
via MITRE·12:51 PM
Data Sourced
via MITRE·12:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that the attacker must already have high privileges. Exploitation does not require user interaction and can be performed over the network.
2
What is the potential impact if exploitation succeeds?
An attacker or unauthorized user could introduce unverified, malicious, or broken code directly into production environments. The reported CVSS impacts include high confidentiality, integrity, and availability impact.