CVE-2025-68825 HIGH

CVE-2025-68825: HCL Hive is affected by incorrect default permissions

Vendor Hclsoftware
Product HCL Hive
Weakness CWE-276
Published August 24, 2026
Last update August 24, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.

Key dates

02Disclosure timeline

August 24, 2026 CVE published