Executive brief
HCL Hive, an enterprise application platform, exposes its API documentation through publicly accessible Swagger interfaces without requiring authentication. While no credentials or personal data were directly exposed, this publicly visible documentation reveals the internal API structure and endpoints, making it easier for attackers to understand and target the application's attack surface.
Technical details
This vulnerability is an information exposure flaw in HCL Hive's API documentation exposure. The Swagger/OpenAPI documentation endpoint is accessible to unauthenticated users, revealing API endpoints, parameters, and structure without authentication checks. The attack vector is network-based with no preconditions—any remote attacker can access the endpoint to enumerate APIs. Although no sensitive data like credentials or PII was embedded in the documentation itself, the exposure significantly increases reconnaissance capabilities for threat actors planning targeted attacks. A patch or configuration update to restrict Swagger documentation access is expected from HCL.
Affected products
- HCL Hive
Timeline
- 2026-08-24: disclosed