CVE-2026-21767 PUBLISHED

HCL BigFix Platform is affected by insufficient authentication

Assigner: HCL
Reserved: 05.01.2026 Published: 01.04.2026 Updated: 01.04.2026

HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4

Product Status

Vendor HCLSoftware
Product BigFix Platform
Versions Default: unaffected
  • Version 11.0.0 - 11.0.5 is affected

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE