HCL Technologies has released security updates for five vulnerabilities in HCL BigFix Service Management, affecting versions 23 and 27. The flaws comprise three critical and two high-severity issues, with CVSSv3 scores ranging from 7.6 to 9.8. No active exploitation has been confirmed.
The most serious issue, CVE-2026-67100, is rated 9.8 and involves SQL injection and cross-tenant data exposure. According to the report, an unauthenticated attacker could manipulate request values to access personal profile data and personally identifiable information belonging to other organisations. CVE-2026-67101, rated 9.3, enables server-side request forgery, while CVE-2026-67102 involves broken access controls and CVE-2026-67103 concerns cross-site scripting.
CVE-2026-18963, rated 9.1, affects the Keycloak identity component’s credential-reset process. The reported flaw could allow an unauthenticated remote attacker to trigger a password reset without the target confirming the request, potentially leading to administrative account takeover. HCL has addressed all five issues through a unified v27 hotfix.
Administrators should consult HCL’s support bulletin for upgrade instructions; those unable to patch immediately are advised to limit administrative access to trusted internal networks.