CVE-2024-30148: Hcltech Hcl Leap

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

Affected products

  • Hcltech Hcl Leap: before 9.3.8 (fixed in 9.3.8)

Published 2025-04-24. Last modified 2026-06-17.