CVE-2026-56590: HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise.
Affected Software
Event History
Frequently Asked Questions
What access and interaction are required for exploitation?
The CVSS vector indicates network access, high attack complexity, low privileges, and required user interaction. However, the description says an unauthenticated attacker could upload and execute a malicious payload, so the supplied information is inconsistent about whether authentication is required.
What is the potential impact if exploitation succeeds?
Successful exploitation could allow upload and execution of malicious payloads and result in complete compromise of the affected server. The CVSS metrics identify high confidentiality and integrity impact, with no availability impact listed.