Junglewise Threat Intelligence

CVE-2026-21821: HCL BigFix SCM Reporting use of end-of-life jQuery 1.x library

CVE-2026-21821 · Severity: high · CVSS 8.3 · Published 2026-05-13

Vendors: HCL.

Executive brief

HCL BigFix SCM Reporting, a tool used for security configuration management and compliance reporting, uses an obsolete version of the jQuery software library. Because this library is no longer supported, it contains known security flaws that could allow attackers to perform malicious actions on a user's computer when they visit the reporting site. This could lead to unauthorized access to sensitive data or the compromise of user sessions.

Technical details

The HCL BigFix SCM Reporting site is vulnerable due to the use of an unmaintained third-party component (CWE-1104), specifically jQuery 1.x. This version of jQuery has reached end-of-life and contains several publicly known vulnerabilities that will not be patched. An attacker can leverage these flaws via a network-based attack, typically requiring some level of user interaction (UI:R), to execute arbitrary JavaScript in the context of the user's browser session. This can result in a full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) for the affected web session. Users are advised to refer to HCL security bulletin KB0130744 for remediation steps.

Affected products

  • HCL BigFix SCM Reporting site

Timeline

  • 2026-05-13: advisory: Initial disclosure by HCL Software
  • 2026-05-13: disclosed

References