CVE-2026-67102: HCL BigFix Service Management is affected by multiple security vulnerabilities.
Published Sep 18, 2026
·Updated
HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles.
Affected Software
1 affected component
HCL BigFix Service Management
Event History
Sep 18, 2026
CVE Published
via MITRE·07:54 AM
Data Sourced
via MITRE·07:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs a low-privileged account. No user interaction is required, and the attack vector is network-based.
2
What could an attacker do if exploitation succeeds?
A low-privileged user could access administrative screens and functions that are intended for higher-privileged roles. This can affect confidentiality and integrity, while no availability impact is identified in the provided severity vector.