
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-56582 is a cryptographic vulnerability in HCL MyCloud caused by the well-known LUCKY13 attack against TLS/SSL implementations. An authenticated network attacker can exploit this padding oracle weakness to decrypt sensitive information transmitted over TLS/SSL connections. The affected version is HCL MyCloud 10.8.2, while version 10.8.1 is listed as the vulnerable CPE entry in some sources. It was published on July 21, 2026, with a CVSS v3.1 base score of 3.1 (Low) (GitHub Advisory, HCL Advisory).
The vulnerability is classified under CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), stemming from HCL MyCloud's use of a TLS/SSL implementation susceptible to the LUCKY13 timing side-channel attack. LUCKY13 exploits differences in processing time when handling CBC-mode cipher suites with MAC-then-encrypt padding, allowing an attacker to distinguish between valid and invalid padding through timing measurements — a classic padding oracle attack. Exploitation requires network access, low-level authentication, and high attack complexity, as the attacker must perform precise timing measurements across many crafted TLS records (GitHub Advisory, HCL Advisory).
Successful exploitation is limited to a confidentiality impact — an authenticated attacker can potentially decrypt sensitive information transmitted over TLS/SSL connections, such as session tokens, credentials, or application data. There is no integrity or availability impact. The attack scope is unchanged, meaning it does not enable lateral movement or privilege escalation beyond the decryption of intercepted traffic (GitHub Advisory).
HCL has published a knowledge base article (KB0132381) addressing this vulnerability. Organizations should consult the HCL advisory for patched version details and apply the recommended update to HCL MyCloud. As a configuration-level mitigation, enforce TLS 1.2 or higher and disable CBC-mode cipher suites vulnerable to LUCKY13 (e.g., TLS_RSA_WITH_AES_128_CBC_SHA), preferring AEAD cipher suites such as AES-GCM. Network-level TLS inspection and monitoring for anomalous decryption patterns can provide additional defense-in-depth (HCL Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."