Server-Side Request Forgery Vulnerability in HCL BigFix Service Management
CVE-2026-67101

9.3CRITICAL

What is CVE-2026-67101?

HCL BigFix Service Management has a vulnerability in its search functionality that exposes it to server-side request forgery (SSRF) attacks. This flaw permits an attacker to manipulate requests, compelling the application server to communicate with internal systems that ordinarily remain protected from external access. Such exploitation could lead to unauthorized exposure of sensitive information and potential breaches within the internal network. It is critical for users to assess their systems and apply necessary security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

HCL BigFix Service Management V23

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.