CVE-2026-21754CWE-1004

CVE-2026-21754

Medium · published August 25, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
3.7
In the wild
Unconfirmed
What it is

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00141 · 3.7th percentile
Weakness
CWE-1004 · Sensitive Cookie Without 'HttpOnly' Flag
Published
2026-08-25T15:16Z
References (1)
EPSS history
Timeline
  • 27 AUG 06:21Z
    EPSS moved — → 0%
    epss
  • 25 AUG 10:51Z
    HCL Hive is affected by multiple security vulnerabilities.
    cvelistv5