Executive brief
HCL Hive is a collaboration platform used by enterprises for data sharing and workflow management. A vulnerability allows attackers to access sensitive information about the host environment, potentially exposing system details and configuration data that could be used to plan further attacks.
Technical details
HCL Hive contains an information disclosure vulnerability that permits an attacker to gather sensitive details about the host environment. The vulnerability appears to be directly accessible over the network without requiring authentication. An attacker can extract system configuration, environment variables, or other sensitive host information that could facilitate reconnaissance or secondary attacks. The reported CVSS score is 3.7 (low), and no public exploit activity has been observed. Patch availability should be verified with HCL-Software support.
Affected products
- HCL Hive
Timeline
- 2026-08-25: disclosed