CVE-2026-21790
Received Received - Intake
Weak HTTP Header Validation in HCL Traveler Enables Auth Bypass

Publication date: 2026-03-24

Last updated on: 2026-03-24

Assigner: HCL Software

Description
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-24
Last Modified
2026-03-24
Generated
2026-06-16
AI Q&A
2026-03-24
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hcl traveler *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

HCL Traveler has a vulnerability related to weak default HTTP header validation. This weakness could allow an attacker to bypass additional authentication checks that are normally in place.

Impact Analysis

This vulnerability could allow an attacker to bypass authentication mechanisms, potentially leading to unauthorized access. This may result in limited confidentiality, integrity, and availability impacts as indicated by the CVSS score.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21790. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart