6.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Description
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
Basic Information
ID
CVE-2026-21790
Source
HCL
Published
Mar 24, 2026 at 20:04
Modified
Mar 24, 2026 at 20:28
Affected Product
Vendor
HCLSoftware
Product
Traveler
Version
< 14.5.1.0
Affected Versions
HCLSoftware Traveler < 14.5.1.0