Executive brief
HCL BigFix Service Management is a platform used for IT service management and operations. An authenticated user with legitimate access can exploit improper access controls to view sensitive data belonging to other tenants, potentially exposing customer information across multiple organizations that share the same instance.
Technical details
This vulnerability is a security misconfiguration affecting access control enforcement in HCL BigFix Service Management. An authenticated attacker can bypass or circumvent tenant isolation controls to view restricted data across tenant boundaries. The vulnerability requires prior authentication, limiting the attack surface to users with valid credentials. An attacker can gain unauthorized visibility of sensitive information from other tenants sharing the same infrastructure, compromising data confidentiality and potentially regulatory compliance. Patch availability information is referenced in HCL support documentation KB0133917.
Affected products
- HCL BigFix Service Management
Timeline
- 2026-09-18: disclosed