CVE-2026-21761: CORS Misconfiguration in DevOps Loop
Published Jul 17, 2026
·Updated
HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains.
Affected Software
2 affected components
HCL DevOps Loop
hcltech Devops Loop=2.0.0
Event History
Jul 17, 2026
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21761?
The severity of CVE-2026-21761 is rated as medium with a score of 4.2.
2
What vulnerability does CVE-2026-21761 address?
CVE-2026-21761 addresses a CORS misconfiguration in HCL DevOps Loop that may allow unauthorized cross-origin requests.
3
How do I fix CVE-2026-21761?
To fix CVE-2026-21761, review and update the CORS configuration to limit access only to trusted domains.
4
What are the potential risks of CVE-2026-21761?
The potential risks of CVE-2026-21761 include unauthorized access to application resources from untrusted domains.
5
When was CVE-2026-21761 published?
CVE-2026-21761 was published on July 17, 2026.