Administrative Session Concurrency Vulnerability in HCL BigFix Service Management
CVE-2026-21806
3.1LOW
What is CVE-2026-21806?
The administrative session concurrency vulnerability in HCL BigFix Service Management allows multiple authenticated sessions for the same administrative account. This characteristic can be exploited by malicious actors to predict or hijack legitimate session identifiers. If successfully executed, an attacker could take over affected administrative sessions, granting them full privileges to perform unauthorized actions within the system. It is crucial for administrators to recognize and mitigate this risk to maintain the integrity and security of their environments.
Affected Version(s)
HCL BigFix Service Management Version 27
