CVE-2024-23586: Hcltech Hcl Nomad

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

Affected products

  • Hcltech Hcl Nomad: before 1.0.13 (fixed in 1.0.13)

Published 2024-09-27. Last modified 2026-06-17.