Description
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.
Published: 2026-09-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Client‑Side XSS leading to session hijacking
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw that allows an attacker to inject unsanitized JavaScript into the HCL BigFix Service Management web interface. If a victim navigates to a crafted page or receives manipulated content, the malicious script executes in that user’s browser. This attack vector enables the attacker to hijack the user’s session, take over the account, and perform any authorized actions on the victim’s behalf.

Affected Systems

HCL Software’s BigFix Service Management product is affected. The advisory does not specify exact versions, so all releases that contain the vulnerable code should be examined for the flaw.

Risk and Exploitability

The CVSS base score of 7.6 indicates high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure a user to a maliciously crafted page or convince the user to load untrusted content, meaning the attack relies on user interaction and social engineering.

Generated by OpenCVE AI on September 19, 2026 at 20:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch released by HCL for BigFix Service Management as described in the vendor’s support article
  • Ensure that all user‑supplied data displayed by the application is properly sanitized and HTML‑escaped to block script injection
  • Deploy a Web Application Firewall or configure Content Security Policy headers to block inline scripts and restrict script sources to trusted domains

Generated by OpenCVE AI on September 19, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:hcltech:bigfix_service_management:23:-:*:*:*:*:*:*
cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T17:29:54.098Z

Reserved: 2026-07-28T13:24:20.405Z

Link: CVE-2026-67103

cve-icon Vulnrichment

Updated: 2026-09-18T17:29:49.908Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T08:17:00.977

Modified: 2026-10-08T20:32:45.810

Link: CVE-2026-67103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')