AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-56458

MEDIUM · CVSS 5.4 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

HCL DevOps Deploy is vulnerable due to improper configuration of Cross-Origin Resource Sharing (CORS), allowing attackers to perform unauthorized privileged actions and access sensitive information from untrusted domains. Organizations using this software should prioritize addressing this vulnerability to mitigate potential data breaches and unauthorized access risks.

CVE
CVE-2026-56458
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%

Original NVD Description

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

Related CVEs

Other vulnerabilities affecting the same vendor(s)