HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data…
cve CVE-2026-67106 2 sources, 2 claims · Watch
NVD writes:
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. the claim
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. the claim
- Severity
- medium GitHub advisoriesMEDIUM NVD
- CVSS
- 5.3 GitHub advisories5.3 NVD
- Vendor
- HCL Software NVD
- Product
- HCL BigFix Service Management NVD
- CWE
- CWE-200 GitHub advisoriesCWE-200, CWE-209 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-10-01 | first spoke of it: HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two... | GitHub advisories |
| 2026-10-01 | first spoke of it: HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. | NVD |
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.
What it is to other things
| affects | hcltech/bigfix_service_management NVD |
| made_by | hcltech NVD |
In words only, so not counted until a person confirms one:
| made_by | hcl_softwareNVD says “HCL Software” |
| affects | hcl_software/hcl_bigfix_service_managementNVD says “HCL Software · HCL BigFix Service Management” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | yes An attacker can reliably run all of the kill chain's first four steps without a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | GitHub advisories | 5.3receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-67106",
"cvss": {
"score": 5.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-200",
"name": "Exposure of Sensitive Information to an Unauthorized Actor"
}
],
"description": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.",
"ghsa_id": "GHSA-x257-rg92-3rpv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-x257-rg92-3rpv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-x257-rg92-3rpv"
},
{
"type": "CVE",
"value": "CVE-2026-67106"
}
],
"nvd_published_at": "2026-10-01T15:17:31Z",
"published_at": "2026-10-01T15:30:42Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-67106",
"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015",
"https://github.com/advisories/GHSA-x257-rg92-3rpv"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two...",
"type": "unreviewed",
"updated_at": "2026-10-01T15:30:50Z",
"url": "https://api.github.com/advisories/GHSA-x257-rg92-3rpv",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| CVSS cvss | NVD | 5.3receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:Nreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe different words | GitHub advisories | CWE-200receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-67106",
"cvss": {
"score": 5.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-200",
"name": "Exposure of Sensitive Information to an Unauthorized Actor"
}
],
"description": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.",
"ghsa_id": "GHSA-x257-rg92-3rpv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-x257-rg92-3rpv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-x257-rg92-3rpv"
},
{
"type": "CVE",
"value": "CVE-2026-67106"
}
],
"nvd_published_at": "2026-10-01T15:17:31Z",
"published_at": "2026-10-01T15:30:42Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-67106",
"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015",
"https://github.com/advisories/GHSA-x257-rg92-3rpv"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two...",
"type": "unreviewed",
"updated_at": "2026-10-01T15:30:50Z",
"url": "https://api.github.com/advisories/GHSA-x257-rg92-3rpv",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| CWE cwe different words | NVD | CWE-200, CWE-209receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | HCL BigFix Service Managementreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | GitHub advisories | mediumreceipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-67106",
"cvss": {
"score": 5.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-200",
"name": "Exposure of Sensitive Information to an Unauthorized Actor"
}
],
"description": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.",
"ghsa_id": "GHSA-x257-rg92-3rpv",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-x257-rg92-3rpv",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-x257-rg92-3rpv"
},
{
"type": "CVE",
"value": "CVE-2026-67106"
}
],
"nvd_published_at": "2026-10-01T15:17:31Z",
"published_at": "2026-10-01T15:30:42Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-67106",
"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015",
"https://github.com/advisories/GHSA-x257-rg92-3rpv"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two...",
"type": "unreviewed",
"updated_at": "2026-10-01T15:30:50Z",
"url": "https://api.github.com/advisories/GHSA-x257-rg92-3rpv",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Severity severity | NVD | MEDIUM From 4.0 to 6.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | medium | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | partial The attacker gains limited control, or limited information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | HCL Softwarereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks."
}
],
"id": "CVE-2026-67106",
"lastModified": "2026-10-05T17:25:11.243",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67106",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:17:11.124016Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.363",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-200"
},
{
"lang": "en",
"value": "CWE-209"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks. zetlyn/cve-nvd · 2026-10-01 | automatable yes cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cwe CWE-200, CWE-209 exploitation none product HCL BigFix Service Management severity MEDIUM status Analyzed technical_impact partial vendor HCL Software | source |
| HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two... zetlyn/cve-ghsa · 2026-10-01 | cvss 5.3 cwe CWE-200 severity medium | source |