CVE-2026-67103 PUBLISHED

HCL BigFix Service Management is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 28.07.2026 Published: 18.09.2026 Updated: 18.09.2026

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
CVSS Score: 7.6

Product Status

Vendor HCL Software
Product HCL BigFix Service Management
Versions Default: unaffected
  • Version V23 is affected

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE