PT-2026-95304 · Hcl · Bigfix Service Management

CVE-2026-67100

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HCL BigFix Service Management (affected versions not specified)
Description An authenticated attacker can exploit a SQL Injection flaw and a Cross-Tenant Data Exposure flaw. These issues allow the injection of database commands to extract sensitive system details and the manipulation of request values to gain unauthorized access to full personal profile data and Personally Identifiable Information (PII) across different organizations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67100

Affected Products

Bigfix Service Management