securityonline.info 18 Sept 2026, 09:25 UTC

HCL BigFix Flaws Expose Cross Tenant Data and Admin Accounts

HCL BigFix Flaws Expose Cross Tenant Data and Admin Accounts
CyberSIXT Evidence Panel Source marked as original reporting

HCL Technologies has released security updates for five vulnerabilities in HCL BigFix Service Management, affecting versions 23 and 27. The flaws comprise three critical and two high-severity issues, with CVSSv3 scores ranging from 7.6 to 9.8. No active exploitation has been confirmed.

The most serious issue, CVE-2026-67100, is rated 9.8 and involves SQL injection and cross-tenant data exposure. According to the report, an unauthenticated attacker could manipulate request values to access personal profile data and personally identifiable information belonging to other organisations. CVE-2026-67101, rated 9.3, enables server-side request forgery, while CVE-2026-67102 involves broken access controls and CVE-2026-67103 concerns cross-site scripting.

CVE-2026-18963, rated 9.1, affects the Keycloak identity component’s credential-reset process. The reported flaw could allow an unauthenticated remote attacker to trigger a password reset without the target confirming the request, potentially leading to administrative account takeover. HCL has addressed all five issues through a unified v27 hotfix.

Administrators should consult HCL’s support bulletin for upgrade instructions; those unable to patch immediately are advised to limit administrative access to trusted internal networks.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline