CVE-2026-56595

Summary

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.

Affected Software

VendorProductVersion RangeStatus
HCL SoftwareHCL BigFix Service Managementv27affected

Weaknesses

  • CWE-942: CWE-942 Permissive Cross-domain Security Policy with Untrusted Domains

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References