Executive brief
HCL Hive is software used for collaboration and document management. The product depends on third-party components that contain publicly known security vulnerabilities. An attacker could exploit these flaws to gain unauthorized access to the system or compromise its data and operations.
Technical details
HCL Hive is affected by the use of vulnerable third-party components, which introduces publicly documented security flaws into the product. The specific vulnerable component and its CVE are not detailed in the advisory, but the attack surface is the third-party dependency chain. An attacker with network access can exploit these known vulnerabilities without authentication or user interaction to achieve unauthorized system access or compromise. HCL has published advisory KB0131731 indicating a patch or mitigation is available.
Affected products
- HCL Hive
Timeline
- 2026-08-24: disclosed