Description
HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.
Published: 2026-09-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to protected resources and APIs
Action: Patch
AI Analysis

Impact

The vulnerability arises from an improperly validated Origin header that allows an attacker to craft a malicious web page capable of sending requests to the vulnerable HCL BigFix Service Management instance on the victim's behalf. The misuse of CORS controls can result in unauthorized reading of or manipulation of protected data and restricted API endpoints, potentially leading to data disclosure, policy violation, or unauthorized configuration changes.

Affected Systems

The affected product is HCL BigFix Service Management from HCL Software. Version information is not provided, so any installation of the product remains potentially at risk until a patch or configuration change is applied. The vulnerability is specific to the cross‑origin behavior of the web interface, making all network‑exposed instances susceptible.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity, and an EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker would need to lure a user into visiting a malicious page that issues HTTP requests to the BigFix service; the attack therefore relies on social engineering or compromised content to be served to an authenticated browser session. Because the flaw is limited to improper origin validation, there is no immediate code execution or privilege escalation beyond the browser's context.

Generated by OpenCVE AI on September 19, 2026 at 20:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HCL BigFix Service Management patch that corrects the CORS validation.
  • Configure the web server or application to allow CORS requests only from trusted domains by validating the Origin header against an allowlist.
  • Implement network controls to restrict inbound HTTP/S traffic to BigFix endpoints to known administrator IP ranges.

Generated by OpenCVE AI on September 19, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-942
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T10:50:27.003Z

Reserved: 2026-06-22T13:40:03.377Z

Link: CVE-2026-56595

cve-icon Vulnrichment

Updated: 2026-09-18T10:50:22.472Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:41.900

Modified: 2026-09-18T13:44:57.517

Link: CVE-2026-56595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-942

    Permissive Cross-domain Security Policy with Untrusted Domains