CVE-2026-21753CWE-1104
CVE-2026-21753
Medium · published August 25, 2026
What it is
HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
The record
Technical detail
- CVSS v3.1
- 4.2 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00139 · 3.6th percentile
- Weakness
- CWE-1104 · Use of Unmaintained Third Party Components
- Published
- 2026-08-25T15:16Z
References (1)
EPSS history
Timeline