Junglewise Threat Intelligence

CVE-2026-56581: HCL MyCloud missing cookie path attribute

CVE-2026-56581 · Severity: low · CVSS 2.6 · Published 2026-07-21

Technologies: HCL Software MyCloud. Vendors: HCL Software.

Executive brief

HCL MyCloud, a cloud management platform, is affected by a configuration weakness where security attributes are not properly set on session cookies. This flaw could allow an attacker to potentially intercept or access sensitive session data or authentication tokens if they can influence the user's network environment. While the risk is considered low, it could lead to unauthorized access to user accounts under specific conditions.

Technical details

HCL MyCloud version 10.8.2 fails to set the 'Path' attribute for sensitive cookies, a vulnerability classified under CWE-614. This misconfiguration means cookies may be sent to unintended paths within the same domain, increasing the risk of session token leakage. The attack vector is network-based but requires high complexity and user interaction, typically involving a man-in-the-middle scenario or a cross-site scripting (XSS) vector on a sibling path. An attacker with low privileges could potentially capture authentication tokens to gain unauthorized access to the application.

Affected products

  • HCL Software MyCloud 10.8.2

Timeline

  • 2026-07-21: advisory: Initial advisory published by HCL Software
  • 2026-07-21: disclosed: CVE-2026-56581 published to NVD dataset

References

Related threats