Description
HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation allows an attacker to compromise affected administrative sessions and execute actions with full privileged user permissions.
Published: 2026-09-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Session hijacking to gain full administrative privileges
Action: Assess
AI Analysis

Impact

The vulnerability allows an attacker to create multiple simultaneous authenticated sessions for the same administrative account, enabling the prediction or hijacking of valid session identifiers. Once a session is hijacked, the attacker can execute any action with full privileged user permissions, effectively compromising the administrative context.

Affected Systems

HCL Software’s BigFix Service Management product is affected. No specific version information is provided in the available data.

Risk and Exploitability

The CVSS score of 3.1 indicates a low overall risk level, and the EPSS score of 0.00153 (approximately 0.15%) indicates a very low probability of exploitation, suggesting a lack of publicly observed exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is the exploitation of the application’s session management flaw, which could be accessed remotely through the management interface. While the score is low, the impact of a successful session hijack is significant due to the privileged actions that become available to the attacker.

Generated by OpenCVE AI on September 19, 2026 at 19:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch or update for HCL BigFix Service Management available through HCL support.
  • Configure the application to disallow or limit concurrent sessions per administrative account, ensuring only a single active session.
  • Enforce multi‑factor authentication for administrative accounts and, if necessary, reset passwords to reduce credential compromise risk.

Generated by OpenCVE AI on September 19, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation allows an attacker to compromise affected administrative sessions and execute actions with full privileged user permissions.
Title HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (CVE-2026-21806)
Weaknesses CWE-557
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T19:07:27.165Z

Reserved: 2026-01-05T16:08:06.682Z

Link: CVE-2026-21806

cve-icon Vulnrichment

Updated: 2026-09-18T19:07:17.729Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-18T12:17:24.440

Modified: 2026-09-18T20:17:15.447

Link: CVE-2026-21806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses