nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-21762 CVE-2026-21762
LOW
Missing HTTP Security Headers in DevOps Loop
Record summary
CVE-2026-21762 has a selected CVSS score of 3.7 (low).
Description
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DevOps LoopBrowse HCLSoftware / DevOps LoopDefault status: unaffected | CVE List | 2.0.0 | affected |
References
2support.hcl-software.comVendor advisory
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132296