Executive brief
HCL Hive Telco Observability, a platform used by telecommunications providers to monitor network performance, contains a security weakness in its login and identity management component. The web application fails to implement proper Content Security Policy (CSP) directives, which are digital guardrails that prevent unauthorized scripts from running. If exploited, this could allow attackers to perform malicious actions in a user's browser, potentially leading to data theft or unauthorized account access.
Technical details
A vulnerability exists in the Keycloak component of HCL Hive Telco Observability due to missing essential Content Security Policy (CSP) directives. This misconfiguration allows for the bypass of browser-side security controls intended to prevent unauthorized resource loading and script execution. An unauthenticated remote attacker can exploit this by inducing a user to interact with a malicious link or site (UI:R), potentially leading to Cross-Site Scripting (XSS) or clickjacking attacks. Successful exploitation can result in high impacts to confidentiality and integrity as the attacker may execute arbitrary scripts in the context of the victim's session. The issue is tracked as CVE-2025-59874 with a CVSS base score of 8.1.
Affected products
- HCL Hive Telco Observability
Timeline
- 2026-06-04: disclosed: Initial NVD publication date
- 2026-06-04: advisory: HCL Software security bulletin published