Description
HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.
Published: 2026-08-25
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch or Mitigate
AI Analysis

Impact

An information‑disclosure flaw in HCL Hive allows an adversary to learn details about the host environment, potentially revealing sensitive configuration data or system attributes. The weakness is a classic data‑leak condition that could assist attackers in crafting further attacks or compromising surrounding infrastructure. This vulnerability is catalogued as CWE‑200.

Affected Systems

The defect affects the HCL Software Hive product. No specific version numbers are listed in the CNA data, so the vulnerability could apply to any installed instance of Hive that has not been updated to a patched release. Administrators should verify the exact version in use and cross‑check with HCL’s support resources for applicable patches.

Risk and Exploitability

With a CVSS score of 3.7 the severity is considered low, and there is no EPSS data available to gauge exploitation likelihood. The vulnerability is not present in the CISA KEV catalog, indicating that no widespread exploits have been reported. However, an attacker who can harness this information leak may use it to aid more targeted attacks. The exposure is local or network‑limited; an attacker would need some degree of access to the Hive interface or to the host system. While the flaw alone does not provide privilege escalation or remote code execution, the disclosed data can aid reconnaissance efforts that could lead to higher‑impact exploits.

Generated by OpenCVE AI on August 25, 2026 at 12:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HCL Hive patch or upgrade to a non‑vulnerable release
  • Where patching is delayed, restrict external access to the Hive interface and enforce the principle of least privilege for all user accounts
  • Monitor access logs for anomalous read requests and conduct regular security reviews to ensure no sensitive host data is exposed

Generated by OpenCVE AI on August 25, 2026 at 12:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.
Title HCL Hive is affected by multiple security vulnerabilities.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-25T13:27:58.160Z

Reserved: 2026-01-05T16:07:55.983Z

Link: CVE-2026-21758

cve-icon Vulnrichment

Updated: 2026-08-25T13:27:53.533Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T11:16:51.917

Modified: 2026-08-28T15:46:19.387

Link: CVE-2026-21758

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T12:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor