CVE-2026-56581
LOW
2.6
CVSS 3.1
Description
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.
Metadata
Severity & Metrics
2.6
LOW CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| HCLSoftware | MyCloud | — | 10.8.2 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-614 | cna | CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 2.6 | LOW | 3.1 | cna | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |