Insecure Cookie Attribute Configuration in HCL BigFix Service Management
CVE-2026-56599
2.2LOW
What is CVE-2026-56599?
HCL BigFix Service Management is compromised due to its configuration of cookie attributes, which lack essential security features like SameSite, HttpOnly, Secure flags, and restricted Paths. This insufficiency allows attackers to initiate Cross-Site Request Forgery (CSRF) attacks, exploit Cross-Site Scripting (XSS), and potentially gain unauthorized access to user sessions, posing a significant threat to the integrity and security of user data.
Affected Version(s)
HCL BigFix Service Management Version 27
