
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56581 is a low-severity cookie misconfiguration vulnerability in HCL MyCloud version 10.8.2, where the Path attribute is not set on sensitive cookies, increasing the risk of unauthorized access to session data or authentication tokens. The vulnerability was published on July 21, 2026, and is classified under CWE-614 (Sensitive Cookie in HTTPS Session Without 'Secure' Attribute). It carries a CVSS v3.1 base score of 2.6 (Low) (GitHub Advisory, HCL Support).
The root cause is CWE-614 — cookies in HCL MyCloud are issued without the Path attribute properly set, meaning they may be transmitted to unintended URL paths within the same domain, potentially exposing session tokens or authentication cookies to unauthorized application components. Exploitation requires an authenticated low-privileged user, network-level access, high attack complexity, and user interaction, mapping to the CAPEC-102 (Session Sidejacking) attack pattern. There are no known public proof-of-concept exploits or detailed technical write-ups available at this time (GitHub Advisory, HCL Support).
Successful exploitation could allow an attacker to intercept or access session data or authentication tokens transmitted to unintended URL paths, resulting in limited confidentiality impact. There is no impact to integrity or availability, and the scope is unchanged, meaning exploitation is confined to the affected component. The risk is further constrained by the requirement for an authenticated low-privileged account and user interaction, limiting the practical blast radius (GitHub Advisory).
HCL has published a knowledge base article (KB0132381) addressing this vulnerability. Administrators should ensure that all sensitive cookies in HCL MyCloud are configured with the Path attribute set to the most restrictive applicable path, and should also enforce the Secure, HttpOnly, and SameSite cookie attributes as defense-in-depth measures. Organizations should review their cookie security policies and apply any available vendor patches or configuration guidance (HCL Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."