Security Misconfiguration in HCL BigFix Service Management
CVE-2026-21848

5MEDIUM

What is CVE-2026-21848?

HCL BigFix Service Management is vulnerable due to security misconfiguration, allowing authenticated attackers to exploit improper access controls. This can lead to the unauthorized viewing of sensitive data across different tenant environments, posing a significant risk to data privacy and security.

Affected Version(s)

HCL BigFix Service Management V23

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.