By vendor
Hcltechsw vulnerabilities
Known CVEs affecting Hcltechsw products, prioritized by severity, with SEC.co remediation and detection guidance.
4 published vulnerabilities
- CVE-2026-56460MEDIUM 6.5
HCL DevOps Deploy and HCL Launch contain an information disclosure vulnerability that allows authenticated users to retrieve sensitive configuration data and secrets through API responses. An attacker with valid credentials could leverage this exposure to understand system architecture, extract credentials, and plan follow-up attacks. The vulnerability requires prior authentication, which moderates immediate risk but significantly impacts organizations relying on these platforms for infrastructure automation.
- CVE-2026-56459MEDIUM 6.2
HCL DevOps Deploy and HCL Launch contain a local information disclosure vulnerability where sensitive data is written to application log files readable by any user on the system. An attacker with local access can read these logs to obtain confidential information, such as credentials, API tokens, or deployment secrets. This is a local-only attack that does not require authentication or user interaction.
- CVE-2026-56458MEDIUM 5.4
HCL DevOps Deploy contains a Cross-Origin Resource Sharing (CORS) configuration flaw that allows attackers to bypass domain restrictions. An attacker can craft a malicious webpage that, when visited by a DevOps Deploy user, performs unauthorized actions or steals sensitive information on behalf of that user. This works because the application does not properly validate which domains are allowed to make cross-origin requests to it.
- CVE-2026-56457MEDIUM 4.3
HCL DevOps Deploy and HCL Launch contain a vulnerability where sensitive information can be exposed in output logs. An attacker who gains access to these logs could potentially retrieve sensitive values associated with deployment steps. This is a low-privilege vulnerability requiring network access and authenticated access to the system.