CVE-2026-21760

MEDIUM

HCLSoftware DevOps Loop - Unauthorized Access to Admin Functionality via Forced Browsing

Title source: rule
STIX 2.1

Description

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints.

References (1)

Core 1

Scores

CVSS v3 4.6
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-425
Status published
Products (1)
HCLSoftware/DevOps Loop 2.0.0
Published Jul 17, 2026
Tracked Since Jul 17, 2026