Insecure Cross-Origin Security Headers in HCL IntelliOps Event Management
CVE-2026-21784

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-21784?

HCL IntelliOps Event Management is compromised by the absence of proper Cross-Origin Security headers. This vulnerability weakens the application's defenses, allowing unauthorized external entities to interact with its environment and resources. Without these security headers, there is an increased risk of exploitation, making it essential for users to implement recommended security practices and configurations.

Affected Version(s)

IEM v1.4.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.