HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-17 17:17
Updated : 2026-08-13 13:10
NVD link : CVE-2026-21760
Mitre link : CVE-2026-21760
CVE.ORG link : CVE-2026-21760
JSON object : View
Products Affected
hcltech
- devops_loop
CWE
CWE-425
Direct Request ('Forced Browsing')
