Description
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
Published: 2026-08-20
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL IntelliOps Event Management contains a least‑privilege violation that permits an attacker who already holds some level of access to elevate privileges and reach resources that should otherwise be inaccessible. This flaw is categorized as CWE‑272.

Affected Systems

HCL IntelliOps Event Management, developed by HCL Software, lacks specified version information, so all releases are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 6.6 indicates moderate risk. The EPSS score is not supplied, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, suggesting no public evidence of exploitation yet. The exact attack vector is not indicated in the advisory, so it may be remote or local, but this is inferred.

Generated by OpenCVE AI on August 20, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or update for HCL IntelliOps Event Management as released by HCL Software.
  • Ensure all users and accounts follow the principle of least privilege, revoking any unnecessary elevated permissions.
  • Audit IEM configurations and logs to detect unauthorized privilege use and adjust settings accordingly.

Generated by OpenCVE AI on August 20, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcl Software
Hcl Software iem
Vendors & Products Hcl Software
Hcl Software iem

Thu, 20 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege that could not be accessed with the attacker's original privileges.
Title HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
Weaknesses CWE-272
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Hcl Software Iem
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-27T16:06:32.895Z

Reserved: 2025-10-10T09:04:02.283Z

Link: CVE-2025-62299

cve-icon Vulnrichment

Updated: 2026-08-27T15:42:10.464Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T13:16:48.503

Modified: 2026-08-28T15:46:19.387

Link: CVE-2025-62299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:30Z

Weaknesses
  • CWE-272

    Least Privilege Violation