CORS Misconfiguration in HCL BigFix Service Management
CVE-2026-56595

3.1LOW

What is CVE-2026-56595?

HCL BigFix Service Management is vulnerable to a misconfiguration in Cross-Origin Resource Sharing (CORS) due to inadequately validated origin headers. This flaw permits attackers to create malicious web pages capable of interacting with the vulnerable application. As a result, attackers may gain unauthorized access to sensitive resources and restricted APIs, potentially compromising user data and application integrity.

Affected Version(s)

HCL BigFix Service Management v27

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.