CVE-2026-67100: Hcltech Bigfix Service Management

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.

Affected products

  • Hcltech Bigfix Service Management: version 23 only; version 27 only

Published 2026-09-18. Last modified 2026-10-08.