Weak Software Supply Chain Governance in HCL Hive
CVE-2026-21753

4.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-21753?

HCL Hive faces challenges related to inadequate software supply chain governance, potentially allowing the introduction of vulnerable, outdated, or malicious third-party dependencies into its application environment. This presents security risks to users as improper management of such dependencies can lead to exploitation and data breaches.

Affected Version(s)

Hive V1.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.