Description
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
Published: 2026-08-24
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized code execution via broken access control
Action: Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated or low‑privileged user to inject unverified or malicious code directly into a production HCL Hive environment. The impact is the potential loss of confidentiality, integrity, or availability of the data and services running on the affected system, as the attacker can alter or compromise application functionality.

Affected Systems

The affected product is HCL Hive, a data processing and analytics platform from HCL Software. No specific versions are listed in the CNA data, so all installations of HCL Hive are considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score is not available, so exploitation probability cannot be quantified, but the vulnerability is listed as not part of the CISA KEV catalog. The likely attack vector is remote, requiring access to the HCL Hive web interface or management console, and the attacker must discover the broken access control to inject code. If exploited, the attacker could gain elevated privileges or execute arbitrary code within the Hive environment.

Generated by OpenCVE AI on August 24, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied fix or upgrade to the latest HCL Hive version following the instructions in the official support article (KB0131731).
  • Limit who can access the Hive configuration or management interfaces and verify that broken access control controls are enforced.
  • Run a comprehensive vulnerability scan to confirm that no remaining access control weaknesses or exposed code injection points exist.

Generated by OpenCVE AI on August 24, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech hive
Vendors & Products Hcltech
Hcltech hive

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
Title HCL Hive is affected by a broken access control vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-24T13:01:26.046Z

Reserved: 2026-01-05T16:07:55.983Z

Link: CVE-2026-21756

cve-icon Vulnrichment

Updated: 2026-08-24T12:59:34.599Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T13:17:32.477

Modified: 2026-08-28T15:46:19.387

Link: CVE-2026-21756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:10:59Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment