Junglewise Threat Intelligence

CVE-2026-21784: HCL IntelliOps Event Management missing CORS security headers

CVE-2026-21784 · Severity: medium · CVSS 4.8 · Published 2026-08-20

Vendors: HCL.

Executive brief

HCL IntelliOps Event Management (IEM) is an event monitoring and management system used to track and respond to infrastructure events. Missing or insecure Cross-Origin Resource Sharing (CORS) headers expose the application to cross-origin attacks, allowing unauthorized external websites to interact with the system and potentially access sensitive data or perform actions on behalf of authenticated users.

Technical details

This vulnerability stems from missing or improperly configured CORS security headers in HCL IntelliOps Event Management. CORS headers control which external domains are permitted to access the application's resources via browser-based requests. Without proper restrictions, an attacker can craft a malicious web page that, when visited by an IEM user, makes unauthorized requests to the IEM instance. This attack typically requires the victim to be authenticated to the IEM application. The vulnerability allows attackers to perform actions or exfiltrate data depending on the victim's permissions and session state. A patch or mitigation guidance is expected from HCL Software.

Affected products

  • HCL IntelliOps Event Management

Timeline

  • 2026-08-20: disclosed

References