CVE-2026-56599 PUBLISHED

HCL BigFix Service Management is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 22.06.2026 Published: 01.10.2026 Updated: 01.10.2026

HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting (XSS), and unauthorized access.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS Score: 2.2

Product Status

Vendor HCL Software
Product HCL BigFix Service Management
Versions Default: unaffected
  • Version Version 27 is affected

References

Problem Types

  • CWE-614 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute CWE