Executive brief
HCL MyCloud, a cloud management platform, is affected by a vulnerability that allows multiple simultaneous logins for the same user account. This flaw increases the risk that an unauthorized person could maintain access to an account or hijack an active session without being disconnected. While the risk is rated as low, it could lead to unauthorized access to sensitive corporate data or account misuse.
Technical details
HCL MyCloud version 10.8.2 is vulnerable to insufficient session expiration (CWE-613), specifically manifesting as a concurrent login vulnerability. The application fails to invalidate existing sessions or prevent multiple simultaneous active sessions for a single user account. An authenticated attacker with network access could exploit this to maintain persistence or perform session hijacking. The vulnerability has a low CVSS score (3.1) because it requires low privileges and high attack complexity, primarily impacting confidentiality. Users are advised to refer to HCL security bulletin KB0132381 for remediation steps.
Affected products
- HCL Software MyCloud 10.8.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory