CVE-2026-21785 PUBLISHED

HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy

Assigner: HCL
Reserved: 05.01.2026 Published: 27.05.2026 Updated: 28.05.2026

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 4

Product Status

Vendor HCLSoftware
Product BigFix Remote Control Server
Versions Default: unaffected
  • Version <= versions 10.1.0.0442 is affected

References

Problem Types

  • CWE-1021 Improper restriction of rendered UI layers or frames CWE