SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-21759

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

HCL Hive is vulnerable due to the public exposure of its Swagger API documentation, which, while not disclosing sensitive information, can still enhance the attack surface for potential exploitation. Organizations using HCL Hive should prioritize addressing this issue to mitigate risks associated with unauthorized access to API functionalities. Security teams should ensure that API documentation is properly secured to prevent information exposure.

CVE
CVE-2026-21759
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%

Original NVD Description

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly.  Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increase the overall attack surface.