Description
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL MyCloud implements a weak password policy that allows user accounts to be protected by passwords that lack requisite complexity, length, or expiration requirements. This weakness increases the likelihood that legitimate usernames and weak passwords can be discovered or guessed, enabling an attacker to gain unauthorized access. The vulnerability is specifically a weakness in password enforcement rather than a flaw that directly allows remote code execution or denial of service.

Affected Systems

The affected product is HCL Software MyCloud; no specific version information is provided, so version details are unavailable.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity, and the EPSS score of less than 1% signifies a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is brute‑force or credential‑based login attempts against the MyCloud authentication interface. No advanced privileges or remote code execution are required; exploitation simply results in unauthorized account access if the attacker guesses or enumerates a valid weak password. The impact is confined to user account integrity and potential access to any resources those accounts control.

Generated by OpenCVE AI on August 1, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enable a strong password policy in HCL MyCloud, requiring a minimum length, character variety, and regular expiration of passwords
  • Configure an account‑lockout mechanism to block repeated failed login attempts after a defined threshold
  • Optionally enforce multi‑factor authentication for all administrative and user accounts to add an additional verification layer

Generated by OpenCVE AI on August 1, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware mycloud
Vendors & Products Hclsoftware
Hclsoftware mycloud

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
Title HCL MyCloud affected by Weak Password Policy
Weaknesses CWE-521
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Hclsoftware Mycloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:26:55.059Z

Reserved: 2026-06-22T13:39:47.964Z

Link: CVE-2026-56577

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:40.374Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:00:04Z

Weaknesses
  • CWE-521

    Weak Password Requirements