Junglewise Threat Intelligence

CVE-2026-21752: HCL Hive use of vulnerable third-party components

CVE-2026-21752 · Severity: high · CVSS 7.5 · Published 2026-08-24

Vendors: HCL.

Executive brief

HCL Hive is software used for collaboration and document management. The product depends on third-party components that contain publicly known security vulnerabilities. An attacker could exploit these flaws to gain unauthorized access to the system or compromise its data and operations.

Technical details

HCL Hive is affected by the use of vulnerable third-party components, which introduces publicly documented security flaws into the product. The specific vulnerable component and its CVE are not detailed in the advisory, but the attack surface is the third-party dependency chain. An attacker with network access can exploit these known vulnerabilities without authentication or user interaction to achieve unauthorized system access or compromise. HCL has published advisory KB0131731 indicating a patch or mitigation is available.

Affected products

  • HCL Hive

Timeline

  • 2026-08-24: disclosed

References