CVE-2026-21765 PUBLISHED

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys

Assigner: HCL
Reserved: 05.01.2026 Published: 01.04.2026 Updated: 01.04.2026

HCL BigFix Platform is affected by insecure permissions on private cryptographic keys.  The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor HCLSoftware
Product BigFix Platform
Versions Default: unaffected
  • Version 11.0.0 - 11.0.5 is affected

References

Problem Types

  • CWE-732 Incorrect Permission Assignment for Critical Resource CWE
  • CWE-276 Incorrect default permissions CWE