CVE-2026-56595 PUBLISHED

HCL BigFix Service Management is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 22.06.2026 Published: 18.09.2026 Updated: 18.09.2026

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS Score: 3.1

Product Status

Vendor HCL Software
Product HCL BigFix Service Management
Versions Default: unaffected
  • Version v27 is affected

References

Problem Types

  • CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains CWE