Stored Cross-Site Scripting Vulnerability in HCL BigFix Service Management
CVE-2026-56589

7.2HIGH

What is CVE-2026-56589?

HCL BigFix Service Management has a vulnerability that allows attackers to inject and store malicious scripts within the application. When a user visits an affected page, these scripts can execute automatically, leading to potential session hijacking and unauthorized access to sensitive user data. Organizations using this product should take immediate steps to remediate this issue to protect their systems and data integrity.

Affected Version(s)

HCL BigFix Service Management Version 27

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.