Information Exposure in HCL Hive API Documentation
CVE-2026-21759
4.3MEDIUM
What is CVE-2026-21759?
HCL Hive suffers from an information exposure vulnerability that permits unauthorized access to publicly available Swagger documentation. This exposure, while not disclosing sensitive information such as credentials or personally identifiable information (PII), still poses risks by broadening the attack surface. Unauthorized users gaining access to API documentation can use the exposed information to identify potential vulnerabilities within the HCL Hive system, emphasizing the importance of securing API endpoints and restricting access to technical documentation.
Affected Version(s)
HCL Hive 1.0
