Description
HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.
Published: 2026-07-21
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, classified as Server Version Disclosure, allows an attacker to obtain the exact software version of a HCL MyCloud instance. The disclosed version can be used to determine other known weaknesses specific to that version. While the vulnerability itself does not provide direct code execution or unauthorized access, the information can lower the barriers to subsequent, more severe attacks. The weakness is identified as CWE‑200 and scored with a CVSS of 2.2, indicating a low severity but non‑negligible concern for systems exposed to external traffic.

Affected Systems

The affected product is HCL Software’s MyCloud platform. No specific version range is listed in the CNA data, so the risk applies generally to all MyCloud installations that reveal version information in server responses. Administrators should verify whether their deployment exposes version details in HTTP headers, error messages, or other publicly accessible areas.

Risk and Exploitability

Because the CVSS is low and the EPSS score is under 1%, the likelihood of this vulnerability being actively exploited today is minimal, and it is not part of the CISA KEV catalog. However, attackers can combine the disclosed version data with other publicly available exploits for that specific MyCloud release. The attack path is most likely a passive reconnaissance step that relies on the server’s exposed version header or default error pages. Mitigation focuses on eliminating the informational leak rather than patching a code flaw that would allow active compromise.

Generated by OpenCVE AI on August 1, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any HCL Software patch or update that removes server version disclosure. If no patch is available, proceed to the next step.
  • Configure the web server or application to suppress or modify the Server and X‑Powered‑By headers so that the software version is not transmitted to clients, using header rewrite rules or disabling automatic header injection.
  • Restrict access to administrative interfaces and error pages to trusted IP ranges or VPNs to limit the amount of visible information to potential attackers.
  • Regularly review security advisories from HCL Software and monitor for new patches addressing information disclosure in MyCloud.

Generated by OpenCVE AI on August 1, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware mycloud
Vendors & Products Hclsoftware
Hclsoftware mycloud

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.
Title HCL MyCloud was affected by Server Version Disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Mycloud
Hcltech Dryice Mycloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:26:48.215Z

Reserved: 2026-06-22T13:39:47.964Z

Link: CVE-2026-56578

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:42.436Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T18:17:01.667

Modified: 2026-08-03T14:40:24.830

Link: CVE-2026-56578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor