2.6
CVE-2026-56581
- EPSS 0.1%
- Veröffentlicht 21.07.2026 17:37:26
- Zuletzt bearbeitet 03.08.2026 14:40:32
- Erkennungen
HCL MyCloud was affected with Cookie Attribute Path Not Set
HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Dryice Mycloud Version 10.8.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.01 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@hcl.com | 2.6 | 1.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
|
CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132381