Back

CRITICAL

HCL DevOps Velocity is susceptible to brute-force attacks

Published Apr 13, 2026

Description

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsuccessful login attempt limit.  This vulnerability is fixed in 5.1.7.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HCL
Published Apr 13, 2026
Updated Apr 13, 2026
Reserved Apr 1, 2025
CISA Vulnrichment
Updated Apr 13, 2026
NVD
Status Analyzed
Modified Jul 7, 2026
Red Hat
Severity n/a
Public date n/a