CVE-2026-21759
Received Received - Intake

Information Exposure in HCL Hive via Swagger Documentation

Vulnerability report for CVE-2026-21759, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: HCL Software

Description

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.Β  Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl hive *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-215 The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL Hive has an information exposure vulnerability where Swagger documentation is publicly accessible. This exposes API details to unauthenticated users, increasing the potential attack surface even though no sensitive data like credentials or PII was found.

Detection Guidance

Check if Swagger documentation is publicly accessible by inspecting web server responses or API endpoints. Use tools like curl to query suspected paths (e.g., /swagger, /api-docs) and verify if documentation is exposed without authentication.

Impact Analysis

Exposing Swagger documentation publicly allows attackers to analyze API endpoints, potentially identifying weaknesses or misconfigurations. This could lead to further exploitation if additional vulnerabilities exist, though no direct sensitive data exposure was confirmed.

Compliance Impact

Exposing Swagger documentation publicly increases the attack surface, which could lead to unauthorized access or data breaches. This may violate compliance requirements under GDPR (data protection) and HIPAA (health data security) by failing to implement proper access controls and risk mitigation measures.

Mitigation Strategies

Restrict access to Swagger documentation by implementing authentication or IP whitelisting. Update HCL Hive to the latest patched version if available. Monitor network traffic for unauthorized access attempts to API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-21759. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart