CVE-2026-21753
HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.2
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- EPSS probability
- 0.14%
- CWE
- CWE-1104
- Published
- 2026-08-25
- Last modified
- 2026-08-25
Affected products
- HCL Software Hive
Weakness type
Related vulnerabilities
- CVE-2026-12554 — HP Easy Start for macOS - Security Update
- CVE-2026-21752 — HCL Hive is affected by a use of vulnerable third-party components
- CVE-2026-66788 — Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag
- CVE-2026-11325 — cloudflare/pages-action is deprecated — migration required by September 18th, 2026
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-56580 — HCL MyCloud was affected by Using Components with Known Vulnerability
- CVE-2026-3031 — Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
- CVE-2023-37524 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service