PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56458 HCLSoftware CVE debrief

CVE-2026-56458 is a medium-severity vulnerability in HCL DevOps Deploy, affecting versions 8.1.0.0 to 8.1.2.7 and 8.2.0.0 to 8.2.2.0. The vulnerability is due to improper CORS configuration, allowing attackers to perform privileged actions and retrieve sensitive information. This issue has a CVSS score of 5.4 and is classified as MEDIUM severity. Users of HCL DevOps Deploy, particularly those in environments where the affected versions are deployed, should be aware of this vulnerability and take necessary actions to mitigate it.

Vendor
HCLSoftware
Product
HCL DevOps Deploy
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-09
Original CVE updated
2026-07-10
Advisory published
2026-07-09
Advisory updated
2026-07-10

Who should care

Users of HCL DevOps Deploy, particularly those in environments where the affected versions are deployed, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. The vulnerability has a CVSS score of 5.4 and is classified as MEDIUM severity. Affected product deployments should be reviewed for exposure, and compensating controls should be considered while remediation is planned.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it could allow attackers to perform privileged actions and retrieve sensitive information.

Recommended defensive actions

  • Inventory and assess HCL DevOps Deploy instances for vulnerability
  • Apply patches or updates to affected versions
  • Implement compensating controls, such as restricting access to sensitive information
  • Monitor for suspicious activity
  • Verify domain name limitations for trusted domains

Evidence notes

The CVE record was published on 2026-07-09T10:16:26.967Z and was last modified on 2026-07-10T16:00:03.797Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and the CVE record. The vulnerability affects HCL DevOps Deploy versions 8.1.0.0 to 8.1.2.7 and 8.2.0.0 to 8.2.2.0. Users should verify their deployments and take necessary actions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-56458 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-56458

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-56458 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56458

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.