Junglewise Threat Intelligence

CVE-2026-67101: HCL BigFix Service Management SSRF in search functionality

CVE-2026-67101 · Severity: critical · CVSS 9.3 · Published 2026-09-18

Vendors: HCL.

Executive brief

HCL BigFix Service Management is an IT service management platform used by organizations to manage and deploy software across large networks. A server-side request forgery (SSRF) vulnerability in its search feature could allow an attacker to trick the application into sending requests to internal systems that should not be accessible from the internet, potentially exposing sensitive internal infrastructure and data.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) in HCL BigFix Service Management's search functionality. The affected component fails to properly validate or restrict the destinations of outbound requests generated through search operations, allowing an attacker to craft malicious requests that force the application server to contact internal systems. The vulnerability is network-accessible and does not require authentication. An attacker can exploit this to enumerate internal services, access internal APIs, or retrieve sensitive information from systems that are isolated from external networks. A patch is available from HCL Software (KB0133782).

Affected products

  • HCL BigFix Service Management <UNKNOWN>

Timeline

  • 2026-09-18: disclosed

References