CVE-2026-56595: HCL BigFix Service Management is affected by multiple security vulnerabilities.
HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker must craft a malicious web page and convince a victim to interact with it. Exploitation relies on the vulnerable application improperly validating the web page's Origin header.
Who is exposed to unauthorized actions?
Victims who interact with an attacker-controlled web page while able to access the affected application may be exposed. The malicious page could interact with protected resources and restricted APIs on the victim's behalf.
What is the expected impact?
The stated impact is unauthorized access to protected resources and restricted APIs, with integrity impact rated low. No confidentiality or availability impact is specified.