CVE-2026-21764

LOW

Insufficient Input Validation in DevOps Loop

Title source: cna
STIX 2.1

Description

HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restricted. This may result in unintended application behavior under certain conditions.

References (1)

Core 1

Scores

CVSS v3 3.1
EPSS 0.0015
EPSS Percentile 5.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
HCLSoftware/DevOps Loop 2.0.0
Published Jul 17, 2026
Tracked Since Jul 17, 2026