Description
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
Published: 2026-08-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Resources
Action: Assess Impact
AI Analysis

Impact

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control, which could allow an attacker to gain unauthorized access to resources. The vulnerability is classified under CWE‑1240, which is related to improper handling of cryptographic contexts, but the description focuses on access control weaknesses rather than cryptographic manipulation. An attacker who can authenticate or manipulate access tokens may read or alter confidential data beyond their intended scope.

Affected Systems

HCL Software’s HCL Hive Keycloak IAM instance is affected. No specific product versions are listed in the data; any installation of HCL Hive should be evaluated for this flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting that it is not currently a high‑profile exploit target. Based on the description, it is inferred that an attacker could exploit the IAM component’s access control granularity by forging or manipulating authentication tokens to access resources beyond their intended scope.

Generated by OpenCVE AI on August 24, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the HCL Software support site for any available patches or updates for HCL Hive and apply them immediately
  • Reconfigure IAM roles and scopes to enforce least privilege, ensuring that permissions are tightly scoped to necessary resources
  • Implement logging and monitoring of authentication and authorization events to detect anomalous access patterns
  • Conduct a security review of the access control configuration to confirm that role boundaries are correctly enforced

Generated by OpenCVE AI on August 24, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech hive
Vendors & Products Hcltech
Hcltech hive

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
Title HCL Hive is affected by use of a cryptographic primitive with a risky implementation
Weaknesses CWE-1240
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-24T15:16:14.563Z

Reserved: 2025-12-24T13:23:45.322Z

Link: CVE-2025-68833

cve-icon Vulnrichment

Updated: 2026-08-24T15:16:09.611Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T14:16:49.623

Modified: 2026-08-28T15:46:19.387

Link: CVE-2025-68833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:48Z

Weaknesses
  • CWE-1240

    Use of a Cryptographic Primitive with a Risky Implementation