Vulnerabilities
46 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-56609 +1 in the same advisory: …56608 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2026-56568 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2026-56538 +1 in the same advisory: …56537 | An endpoint in HCL Connections is vulnerable to information disclosure. An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. NVD description · AI analysis pending | 3.5 | <1% |
| — | ||
| CVE-2026-56577 | HCL MyCloud was affected with Weak Password Policy. HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2026-56584 | HCL IEM was affected with the Information disclosure nginx server. HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. NVD description · AI analysis pending | 5.3 group max | <1% |
| — | ||
| CVE-2023-37507 +1 in the same advisory: …37508 | HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed. NVD description · AI analysis pending | 6.9 group max | <1% |
| — | ||
| CVE-2026-21761 | HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to untrusted domains. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2026-56453 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or authorization logic to bypass controls and gain unauthorized access to targeted user accounts. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2026-35147 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials. NVD description · AI analysis pending | 8.2 group max | <1% |
| — | ||
| CVE-2026-56458 | HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-56457 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2023-37524 +1 in the same advisory: …59868 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party components. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2024-23581 | The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. NVD description · AI analysis pending | 7.8 | <1% |
| — |