Executive brief
HCL BigFix Service Management is a service management platform used to manage IT operations and services. A misconfiguration in how the application validates cross-origin requests allows an attacker to craft a malicious webpage that tricks a victim into accessing protected resources and APIs without authorization on their behalf.
Technical details
The vulnerability is a Cross-Origin Resource Sharing (CORS) misconfiguration caused by improper validation of Origin headers in HCL BigFix Service Management. An attacker can craft a malicious web page that, when visited by an authenticated victim, makes requests to the vulnerable application. Because origin validation is not properly enforced, the application will honor these cross-origin requests, allowing unauthorized access to protected resources and restricted APIs. This is a client-side exploitation technique requiring user interaction (victim must visit attacker-controlled page) but does not require network-level access beyond typical web browsing.
Affected products
- HCL BigFix Service Management
Timeline
- 2026-09-18: disclosed