Junglewise Threat Intelligence

CVE-2026-67102: HCL BigFix Service Management broken access control

CVE-2026-67102 · Severity: high · CVSS 8.1 · Published 2026-09-18

Vendors: HCL Software.

Executive brief

HCL BigFix Service Management is a platform for IT operations and service management that allows organizations to manage patches, configurations, and IT services across their infrastructure. A broken access control vulnerability allows low-privileged users to bypass authorization checks and access administrative functions intended only for higher-privileged roles, potentially leading to unauthorized system configuration changes or data exposure.

Technical details

This is a broken access control vulnerability (CWE-639/CWE-284) in HCL BigFix Service Management that allows authentication bypass or privilege escalation. A low-privileged authenticated user can access administrative screens and functions reserved for higher-privileged roles due to insufficient authorization validation on sensitive endpoints or operations. The vulnerability is network-accessible to authenticated users and does not require additional user interaction. An attacker with low-privilege credentials can exploit this to perform administrative actions, modify system settings, or access sensitive data. Patches are available from HCL Software.

Affected products

  • HCL Software BigFix Service Management

Timeline

  • 2026-09-18: disclosed

References