CVE-2026-21765: HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21765?
CVE-2026-21765 has been classified as a significant vulnerability due to insecure permissions on private cryptographic keys.
How do I fix CVE-2026-21765?
To fix CVE-2026-21765, you should review and tighten the file system permissions for private cryptographic keys in the HCL BigFix Platform.
What systems are affected by CVE-2026-21765?
CVE-2026-21765 specifically affects the HCL BigFix Platform installed on Windows host machines.
What are the implications of CVE-2026-21765?
The implications of CVE-2026-21765 include potential unauthorized access to sensitive data due to overly permissive access to cryptographic keys.
When was CVE-2026-21765 disclosed?
CVE-2026-21765 was disclosed as a security vulnerability impacting the HCL BigFix Platform.