Description
HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthorized actor to observe a license key in a standard HTTP response from HCL MyCloud, exposing a secret credential. This disclosure could enable an attacker to potentially lead to unauthorized access to licensing or administrative functions. The weakness is a classic information disclosure issue (CWE‑200).

Affected Systems

HCLSoftware’s MyCloud platform is affected; no specific product version was listed in the advisory, so all deployments of MyCloud are potentially vulnerable until a mitigation is applied.

Risk and Exploitability

The CVSS base score of 3.1 indicates a low impact, and the EPSS value of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits have been reported. Attackers would need to be able to request the relevant HTTP endpoint and capture the response, which can be performed from any network that can reach the service. Given the low score and scarce evidence of exploitation, the risk is considered minimal but still warrants remediation.

Generated by OpenCVE AI on July 30, 2026 at 16:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch or upgrade to the latest MyCloud release as to MyCloud is served over TLS only and disable any legacy plain‑ access to My access control lists.
  • Implement network segmentation to isolate sensitive MyCloud services from unrestricted traffic.
  • Restrict HTTP access to the license key endpoint by configuring firewall rules so that only trusted internal networks can reach it.

Generated by OpenCVE AI on July 30, 2026 at 16:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware mycloud
Vendors & Products Hclsoftware
Hclsoftware mycloud

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.
Title HCL MyCloud was affected with Exposure of Sensitive Information to an Unauthorized Actor.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Mycloud
Hcltech Dryice Mycloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:26:40.945Z

Reserved: 2026-06-22T13:39:47.964Z

Link: CVE-2026-56579

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:43.826Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T18:17:01.787

Modified: 2026-08-03T14:40:39.553

Link: CVE-2026-56579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:00:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor