Junglewise Threat Intelligence

CVE-2026-21761: HCL DevOps Loop CORS misconfiguration

CVE-2026-21761 · Severity: medium · CVSS 4.2 · Published 2026-07-17

Vendors: HCL Software.

Executive brief

HCL DevOps Loop, a tool used for streamlining development workflows, is affected by a security misconfiguration in how it handles requests from different web domains. This flaw could allow an unauthorized third-party website to interact with the application, potentially leading to the exposure of sensitive internal resources or data. While the risk is mitigated by specific technical requirements, it could compromise the privacy of development operations.

Technical details

HCL DevOps Loop version 2.0.0 contains a Cross-Origin Resource Sharing (CORS) misconfiguration (CWE-942). The application implements a permissive cross-domain policy that fails to properly restrict which origins can access its resources. An authenticated attacker with network access could leverage this misconfiguration to perform unauthorized cross-origin requests. If successful, this allows an untrusted domain to read sensitive data or interact with application resources that should be restricted to the same-origin policy. The vulnerability has a CVSS score of 4.2, reflecting a high complexity of exploitation and the requirement for low-level user privileges.

Affected products

  • HCL Software DevOps Loop 2.0.0

Timeline

  • 2026-07-17: disclosed
  • 2026-07-17: advisory

References