CVE-2026-56599: Hcltech Bigfix Service Management

Low severity, CVSS 2.2. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting (XSS), and unauthorized access.

Affected products

  • Hcltech Bigfix Service Management: version 27 only

Published 2026-10-01. Last modified 2026-10-05.