CVE-2026-67102: Hcltech Bigfix Service Management
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles.
Affected products
- Hcltech Bigfix Service Management: version 23 only; version 27 only
Published 2026-09-18. Last modified 2026-10-08.