Session Management Vulnerability in HCL MyCloud
CVE-2026-56581

2.6LOW

Key Information:

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-56581?

HCL MyCloud has a vulnerability related to the Cookie Attribute Path not being properly set. This oversight may facilitate unauthorized access to session data and authentication tokens, potentially exposing sensitive user information. Addressing this issue is critical to ensuring the integrity and confidentiality of user sessions.

Affected Version(s)

MyCloud 10.8.2

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.