🔐 CVE Alert

CVE-2026-21822

MEDIUM 6.3

A path traversal vulnerability has been identified in HCL AppScan 360° (CVE-2026-21822).

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read or write files outside the intended directory, potentially enabling file system structure inspection or unauthorized file modification within the application's directory scope.

CWE CWE-22
Vendor hcl software
Product hcl appscan 360°
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for hcl software hcl appscan 360°

Be the first to know when new medium vulnerabilities affecting hcl software hcl appscan 360° are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

HCL Software / HCL AppScan 360°
v 2.1.0 and lower

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.hcl-software.com: https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133460