HCL Traveler <14.5.1.0 Weak Header Validation Bypass
CVE-2026-21790 Published on March 24, 2026
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
Vulnerability Analysis
CVE-2026-21790 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
Origin Validation Error
The software does not properly verify that the source of data or communication is valid.
Affected Versions
HCLSoftware Traveler Version < 14.5.1.0 is affected by CVE-2026-21790Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.