Description
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.
Published: 2026-08-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized lateral movement, container breakout, and interception of sensitive internal communications
Action: Apply Patch
AI Analysis

Impact

HCL Hive has a flaw in which default permissions are set incorrectly, giving users or services more access than intended. This misconfiguration can allow a threat actor to move laterally across the environment, escape from restricted containers, and capture confidential internal traffic. The weakness falls under CWE‑276, an insecure permission assignment issue, and if exploited the attacker could compromise multiple services and exfiltrate sensitive data without needing privileged credentials.

Affected Systems

The vulnerability affects HCL Software’s HCL Hive platform. Specific product and version information are not disclosed in the available data, so any installation of HCL Hive that has not been patched to correct the default permissions is potentially susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates substantial risk. While the EPSS score is not provided, the lack of a KEV listing suggests no widespread exploitation has been documented to date. The likely attack vector is an attacker who has already established some foothold, such as a compromised user or container, and who can then leverage the permissive settings to move laterally, break out of container boundaries, or intercept internal communications.

Generated by OpenCVE AI on August 24, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or update that corrects the default permissions for HCL Hive
  • Re‑configure HCL Hive to enforce least‑privilege on all roles and services, reviewing IAM policies and adjusting file system and network permissions as needed
  • Implement monitoring of network flows and container activity to detect unauthorized lateral movement and potential breakout attempts, and log all permission changes for audit

Generated by OpenCVE AI on August 24, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech hive
Vendors & Products Hcltech
Hcltech hive
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.
Title HCL Hive is affected by incorrect default permissions
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-24T20:22:57.951Z

Reserved: 2025-12-24T13:23:45.321Z

Link: CVE-2025-68825

cve-icon Vulnrichment

Updated: 2026-08-24T20:22:36.882Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T16:16:54.693

Modified: 2026-08-28T15:46:19.387

Link: CVE-2025-68825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:34Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions