Description
HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.
Published: 2026-09-18
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Exposure
Action: Patch
AI Analysis

Impact

HCL BigFix Service Management is vulnerable to a security misconfiguration that allows an authenticated attacker to access and view restricted data elements across tenant boundaries. The flaw is an improper implementation of access controls (CWE-284), resulting in unauthorized data exposure.

Affected Systems

The affected product is HCL BigFix Service Management from HCL Software. No specific version information is provided in the CVE data, so all installations of the product should be checked against the vendor advisory.

Risk and Exploitability

The CVSS score of 5.0 classifies the vulnerability as moderate severity. The EPSS score of less than 1% suggests a low probability that this flaw is actively exploited. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attacker must be authenticated and that proper access controls are missing, enabling data leakage across tenant boundaries.

Generated by OpenCVE AI on September 19, 2026 at 20:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch referenced in HCL advisory KB0133917 to fix the access‑control issue
  • Review and correct tenant boundary configurations to ensure proper isolation between tenants
  • Enforce least‑privilege access for authenticated users and restrict administrative functions to a dedicated admin account

Generated by OpenCVE AI on September 19, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T19:13:49.496Z

Reserved: 2026-01-05T16:08:26.972Z

Link: CVE-2026-21848

cve-icon Vulnrichment

Updated: 2026-09-18T19:13:45.690Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-18T09:16:40.117

Modified: 2026-09-18T20:17:15.607

Link: CVE-2026-21848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:54Z

Weaknesses