Administrative Session Concurrency Vulnerability in HCL BigFix Service Management
CVE-2026-21806

3.1LOW

What is CVE-2026-21806?

The administrative session concurrency vulnerability in HCL BigFix Service Management allows multiple authenticated sessions for the same administrative account. This characteristic can be exploited by malicious actors to predict or hijack legitimate session identifiers. If successfully executed, an attacker could take over affected administrative sessions, granting them full privileges to perform unauthorized actions within the system. It is crucial for administrators to recognize and mitigate this risk to maintain the integrity and security of their environments.

Affected Version(s)

HCL BigFix Service Management Version 27

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.