Executive brief
HCL BigFix Service Management is a platform for IT operations and service management that allows organizations to manage patches, configurations, and IT services across their infrastructure. A broken access control vulnerability allows low-privileged users to bypass authorization checks and access administrative functions intended only for higher-privileged roles, potentially leading to unauthorized system configuration changes or data exposure.
Technical details
This is a broken access control vulnerability (CWE-639/CWE-284) in HCL BigFix Service Management that allows authentication bypass or privilege escalation. A low-privileged authenticated user can access administrative screens and functions reserved for higher-privileged roles due to insufficient authorization validation on sensitive endpoints or operations. The vulnerability is network-accessible to authenticated users and does not require additional user interaction. An attacker with low-privilege credentials can exploit this to perform administrative actions, modify system settings, or access sensitive data. Patches are available from HCL Software.
Affected products
- HCL Software BigFix Service Management
Timeline
- 2026-09-18: disclosed