CVE-2026-21759
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-215
- Published
- 2026-08-24
- Last modified
- 2026-08-24
Affected products
- HCLSoftware HCL Hive
Weakness type
Related vulnerabilities
- CVE-2026-79694 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-62652 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware...
- CVE-2026-74799 — SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure
- CVE-2026-44934 — Exposed tokens in SUSE Rancher AI Agent logs
- CVE-2026-40173 — Dgraph: Unauthenticated pprof endpoint leaks admin auth token
- CVE-2026-33247 — NATS credentials are exposed in monitoring port via command-line argv
- CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC
- CVE-2025-12616 — PHPGurukul News Portal settings.py insertion of sensitive information into debugging code