Description
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in HCLMyCloud allows an attacker to initiate multiple concurrent sessions for a single user. This concurrent login flaw is a weakness in authentication enforcement (CWE‑613) and could lead to unauthorized access, session hijacking, or misuse of the account. Based on the description, it is inferred that an attacker must possess valid credentials to create a concurrent session.

Affected Systems

The affected product is HCLSoftware MyCloud. No specific version information is supplied, so all deployments of this product should be evaluated for potential exposure.

Risk and Exploitability

The CVSS base score of 3.1 indicates low severity, and the EPSS score of less than 1% implies a very low likelihood of exploitation. The weakness is not listed in the CISA KEV catalog. Attack scenarios likely require an authenticated session; a legitimate user or attacker with valid credentials could create a second concurrent session, undermining session safety and potentially allowing unauthorized actions.

Generated by OpenCVE AI on July 30, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update or patch released by HCL Software that fixes the concurrent session issue.
  • Configure HCL MyCloud to restrict each account to a single active session per login if an immediate patch is not available.
  • Monitor session logs for unexpected concurrent sessions and investigate anomalies promptly.

Generated by OpenCVE AI on July 30, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware mycloud
Vendors & Products Hclsoftware
Hclsoftware mycloud

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.
Title HCL MyCloud was affected with Concurrent Login Vulnerability.
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Mycloud
Hcltech Dryice Mycloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:26:17.683Z

Reserved: 2026-06-22T13:39:56.746Z

Link: CVE-2026-56583

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:49.954Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T18:17:02.287

Modified: 2026-08-03T14:52:57.113

Link: CVE-2026-56583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:00:07Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration