Junglewise Threat Intelligence

CVE-2026-21756: HCL Hive broken access control vulnerability in code deployment

CVE-2026-21756 · Severity: high · CVSS 7.2 · Published 2026-08-24

Vendors: HCL.

Executive brief

HCL Hive is a development and deployment platform used to manage code in production environments. A broken access control flaw allows attackers or unauthorized users to bypass security checks and inject malicious, unverified, or broken code directly into production, potentially compromising application integrity and availability.

Technical details

The vulnerability is a broken access control issue in HCL Hive that fails to properly validate or restrict user permissions when handling code deployment. An attacker or unauthorized user can leverage inadequate access controls to introduce unverified or malicious code directly into production environments. The attack requires network access to the affected system but may not require prior authentication depending on the specific control weakness. A successful exploit allows an attacker to compromise application integrity, introduce vulnerabilities, or cause service disruption by injecting arbitrary code into production systems. Patches or mitigations should be available from HCL Software via their support portal.

Affected products

  • HCL Hive

Timeline

  • 2026-08-24: disclosed

References