Back to overview

CVE-2026-56581

LOW
2.6
CVSS 3.1
Description
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

Metadata

CVE ID
CVE-2026-56581
State
PUBLISHED
Assigner
HCL
Reserved
2026-06-22 13:39 UTC
Published
2026-07-21 17:37 UTC
Last updated
2026-07-21 17:37 UTC
Primary CWE
CWE-614
CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' …
Vendor / Product
HCLSoftware / MyCloud
Sources
cve.org  ·  NVD

Severity & Metrics

2.6 LOW CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
HCLSoftware MyCloud 10.8.2
Weakness (CWE)
CWESourceDescription
CWE-614 cna CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVSS scores (1)
ScoreSeverityVersionSourceVector
2.6 LOW 3.1 cna CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Back to overview