Description
HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.
Published: 2026-08-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access or compromise via vulnerable third‑party components
Action: Apply Patch
AI Analysis

Impact

HCL Hive incorporates third‑party components that contain publicly documented security flaws. This use of vulnerable components can allow an attacker to gain unauthorized access or otherwise compromise the system. The weakness arises from the integration of untrusted code and is classified as CWE‑1104.

Affected Systems

The affected application is HCL Hive from HCLSoftware. No specific release or version ranges are listed, so the vulnerability may affect any installation that includes the vulnerable third‑party libraries.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, reflecting significant impact if successful exploitation results in unauthorized access. The EPSS score is not available, but the lack of a KEV listing suggests that active exploitation is not currently widespread. The risk remains substantial because the attacker only needs to exploit a known flaw in a third‑party component, which may be possible over a network interface exposed by HCL Hive.

Generated by OpenCVE AI on August 24, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HCL Hive to the latest release that replaces the vulnerable third‑party components, following vendor instructions.
  • Apply any vendor‑provided patches or updates for the third‑party components that are embedded in HCL Hive.
  • If a patch or updated release is not yet available, isolate the HCL Hive instance from untrusted networks, restrict inbound traffic to required ports, and monitor logs for abnormal activity.
  • Review configuration to disable any unused services or interfaces that could expose the vulnerable components to external access.

Generated by OpenCVE AI on August 24, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech hive
Vendors & Products Hcltech
Hcltech hive
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.
Title HCL Hive is affected by a use of vulnerable third-party components
Weaknesses CWE-1104
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-24T20:21:59.411Z

Reserved: 2026-01-05T16:07:55.982Z

Link: CVE-2026-21752

cve-icon Vulnrichment

Updated: 2026-08-24T20:21:55.365Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T16:16:55.663

Modified: 2026-08-28T15:46:19.387

Link: CVE-2026-21752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:36Z

Weaknesses
  • CWE-1104

    Use of Unmaintained Third Party Components