Junglewise Threat Intelligence

CVE-2026-21760: HCL DevOps Loop unauthorized access to admin functionality

CVE-2026-21760 · Severity: medium · CVSS 4.6 · Published 2026-07-17

Vendors: HCL Software.

Executive brief

HCL DevOps Loop, a tool used for streamlining software development workflows, is affected by a security flaw that allows users with low-level access to reach administrative functions. By manually entering specific web addresses, an unauthorized user could bypass standard security menus to view or modify settings they should not have access to. This could lead to unauthorized configuration changes or the exposure of sensitive internal system information.

Technical details

HCL DevOps Loop version 2.0.0 is vulnerable to a Direct Request (Forced Browsing) flaw, categorized as CWE-425. The application fails to perform sufficient authorization checks on specific administrative endpoints, allowing an authenticated user with low privileges to access restricted functionality by navigating directly to the protected URLs. An attacker could exploit this to perform unauthorized administrative actions or access sensitive data. The vulnerability requires network connectivity and a low-privileged account, though the CVSS vector suggests some level of user interaction may be involved.

Affected products

  • HCL Software DevOps Loop 2.0.0

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References