CVE-2026-21790: Hclsoftware Traveler

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.

Affected products

  • Hclsoftware Traveler: before 14.5.1.0 (fixed in 14.5.1.0)

Published 2026-03-24. Last modified 2026-06-17.