CVE-2026-21806: HCL BigFix Service Management was affected with Admin Session Concurrency vulnerability (CVE-2026-21806)
HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized attacker to predict or hijack valid session identifiers. Successful exploitation allows an attacker to compromise affected administrative sessions and execute actions with full privileged user permissions.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs authenticated access with low privileges. Exploitation also has high attack complexity, and the issue involves predicting or hijacking a valid administrative session identifier.
What could an attacker do after successfully exploiting the vulnerability?
A successful attacker could compromise an affected administrative session and perform actions with full privileged user permissions.
Is a default configuration known to be affected?
The available information identifies multiple simultaneous authenticated sessions for the same administrative account as the affected condition. It does not state whether this behavior is enabled by default or requires configuration changes.