Executive brief
HCL Hive is a collaboration platform used for team communication and information management. A missing rate limit vulnerability allows attackers to repeatedly attempt unauthorized login attempts (brute-force or credential stuffing attacks) to gain account access, or flood the service to cause outages. This could result in unauthorized access to sensitive business data or service unavailability.
Technical details
HCL Hive lacks proper rate limiting controls on authentication endpoints, allowing attackers to conduct brute-force or credential stuffing attacks without restriction. The vulnerability is accessed over the network via the authentication mechanism; no prior authentication is required to exploit it. An attacker can systematically attempt to guess valid credentials or replay compromised credentials to gain unauthorized access to accounts, or trigger excessive authentication requests to cause a denial of service. The attack vector is network-based and unauthenticated, making it relatively easy to exploit at scale.
Affected products
- HCL Hive
Timeline
- 2026-08-24: disclosed