CyberRota Analysis
AI-GeneratedHCL DevOps Deploy is vulnerable due to improper configuration of Cross-Origin Resource Sharing (CORS), allowing attackers to perform unauthorized privileged actions and access sensitive information from untrusted domains. Organizations using this software should prioritize addressing this vulnerability to mitigate potential data breaches and unauthorized access risks.
CVE
CVE-2026-56458
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%
Original NVD Description
HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.
Related CVEs
Other vulnerabilities affecting the same vendor(s)