Insecure Cookie Attribute Configuration in HCL BigFix Service Management
CVE-2026-56599

2.2LOW

What is CVE-2026-56599?

HCL BigFix Service Management is compromised due to its configuration of cookie attributes, which lack essential security features like SameSite, HttpOnly, Secure flags, and restricted Paths. This insufficiency allows attackers to initiate Cross-Site Request Forgery (CSRF) attacks, exploit Cross-Site Scripting (XSS), and potentially gain unauthorized access to user sessions, posing a significant threat to the integrity and security of user data.

Affected Version(s)

HCL BigFix Service Management Version 27

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.