Description
HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized administrative access via broken access control
Action: Immediate Patch
AI Analysis

Impact

HCL BigFix Service Management contains a broken access control flaw that permits a low‑privileged user to reach administrative screens and functions normally reserved for higher roles. The vulnerability is a classic example of the weak Role‑Based Access Control weakness identified as CWE‑285 and can lead to elevation of privileges, compromise of configuration data, and potential system disruption.

Affected Systems

The affected product is HCL Software’s HCL BigFix Service Management. No specific patched versions are listed in the CNA data, and the vendor has not provided detailed affected product versions. Administrators should verify whether their installations correspond to the versions referenced in the vendor’s support documentation.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. With an EPSS score of less than 1%, the probability of exploitation in the wild is low but non‑zero. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation has been reported. Exploitation requires legitimate user access; an attacker with a normal user account can navigate to protected administrative interfaces and perform unauthorized actions. No public exploit code is known, but the attack path is straightforward once a valid session exists.

Generated by OpenCVE AI on September 19, 2026 at 20:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the HCL Software security patch for BigFix Service Management that addresses the broken access control flaw.
  • Restrict administrative screen access so that only users with proper administrative roles can view or modify settings; remove or disable privileges for all other accounts.
  • Continuously monitor system logs for unauthorized administrative access attempts and enforce least‑privilege policies.

Generated by OpenCVE AI on September 19, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hcltech:bigfix_service_management:23:-:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T17:31:20.436Z

Reserved: 2026-07-28T13:24:18.240Z

Link: CVE-2026-67102

cve-icon Vulnrichment

Updated: 2026-09-18T17:30:48.540Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T08:17:00.857

Modified: 2026-10-08T20:33:31.500

Link: CVE-2026-67102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:05Z

Weaknesses