CVE-2026-21752
Received Received - Intake

Use of Vulnerable Third-Party Components in HCL Hive

Vulnerability report for CVE-2026-21752, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: HCL Software

Description

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl hive *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1104 The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL Hive uses third-party components with known security flaws. Attackers could exploit these flaws to gain unauthorized access or compromise the system without needing special privileges or user interaction.

Detection Guidance

The provided CVE details do not include specific detection methods or commands. Review the HCL Hive documentation and security bulletin for guidance on identifying vulnerable components.

Impact Analysis

An attacker could access sensitive data, modify system behavior, or disrupt services. The high CVSS score (7.5) indicates significant risk due to potential confidentiality breaches.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating GDPR (data protection) and HIPAA (health data privacy) requirements. Organizations may face legal penalties or compliance failures.

Mitigation Strategies

Update HCL Hive to the latest version to address vulnerable third-party components. Monitor vendor advisories for patches and apply them promptly. Review system access logs for unauthorized activity and restrict unnecessary network access to the system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21752. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart