CVE-2026-21760
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-425
- Published
- 2026-07-17
- Last modified
- 2026-07-17
Affected products
- HCLSoftware DevOps Loop
Weakness type
Related vulnerabilities
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-14953 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access control
- CVE-2026-76799 — code-projects Login Registration System SQL Database Backup login_registration_system.sql file access
- CVE-2026-19903 — SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
- CVE-2026-60011 — Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly...
- CVE-2024-23573 — HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that...
- CVE-2026-13533 — agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
- CVE-2026-10521 — Authenticated unintended access to critical program parameters