CVE-2026-21767

MEDIUM

HCL BigFix Platform is affected by insufficient authentication

Title source: cna
STIX 2.1

Description

HCL BigFix Platform is affected by insufficient authentication.  The application might allow users to access sensitive areas of the application without proper authentication.

Scores

CVSS v3 4.0
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
HCLSoftware/BigFix Platform 11.0.0 - 11.0.5
hcltech/bigfix_platform 11.0.0 - 11.0.5
Published Apr 02, 2026
Tracked Since Apr 02, 2026