Junglewise Threat Intelligence

CVE-2026-21759: HCL Hive information exposure in Swagger documentation

CVE-2026-21759 · Severity: medium · CVSS 4.3 · Published 2026-08-24

Vendors: HCL.

Executive brief

HCL Hive, an enterprise application platform, exposes its API documentation through publicly accessible Swagger interfaces without requiring authentication. While no credentials or personal data were directly exposed, this publicly visible documentation reveals the internal API structure and endpoints, making it easier for attackers to understand and target the application's attack surface.

Technical details

This vulnerability is an information exposure flaw in HCL Hive's API documentation exposure. The Swagger/OpenAPI documentation endpoint is accessible to unauthenticated users, revealing API endpoints, parameters, and structure without authentication checks. The attack vector is network-based with no preconditions—any remote attacker can access the endpoint to enumerate APIs. Although no sensitive data like credentials or PII was embedded in the documentation itself, the exposure significantly increases reconnaissance capabilities for threat actors planning targeted attacks. A patch or configuration update to restrict Swagger documentation access is expected from HCL.

Affected products

  • HCL Hive

Timeline

  • 2026-08-24: disclosed

References