Cross-Site Scripting Vulnerability in HCL BigFix Service Management
CVE-2026-67103

7.6HIGH

What is CVE-2026-67103?

HCL BigFix Service Management is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. This security flaw can lead to serious risks, including session hijacking and account takeover, as attackers can execute unauthorized actions on behalf of affected users. Proper validation and sanitization of user input are critical to mitigate this risk. Organizations utilizing HCL BigFix Service Management should assess their security posture and apply necessary patches or updates to safeguard against potential exploits.

Affected Version(s)

HCL BigFix Service Management V23

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.