Multiple security vulnerabilities affecting HCL BigFix Service Management versions These software defects impact HCL BigFix Service Management version 23 and version 27 have been identified in HCL BigFix Service Management version 23 and version 27, allowing unauthenticated attackers to execute arbitrary database commands and force account password resets. System administrators must apply the newly released v27 hotfix immediately to protect corporate environments from unauthorized access.
CVE-2026-67100 (CVSS 9.8 — Critical): The vulnerability combines SQL Injection and Cross-Tenant Data Exposure, enabling attackers to extract sensitive internal system details by manipulating request values to gain unauthorized access to full personal profile data and PII across different organizations.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting HCL BigFix Service Management versions These software defects impact HCL BigFix Service Management version 23 and version 27 have been identified in HCL BigFix Service Management version 23 and version 27, allowing unauthenticated attackers to execute arbitrary database commands and force account password resets. System administrators must apply the newly released v27 hotfix immediately to protect corporate environments from unauthorized access.
CVE-2026-67100 (CVSS 9.8 — Critical): The vulnerability combines SQL Injection and Cross-Tenant Data Exposure, enabling attackers to extract sensitive internal system details by manipulating request values to gain unauthorized access to full personal profile data and PII across different organizations.[emaillocker id="1283"]
CVE-2026-67101 (CVSS 9.3 — High): The vulnerability enables Server-Side Request Forgery.
CVE-2026-18963: A flaw was found in the reset-credentials flow of the keycloak-services component, allowing an unauthenticated remote attacker to trigger password resets without requiring the target to click a verification link.
CVE-2026-67102: Additional bugs enable broken access controls.
CVE-2026-67103 (CVSS 7.6 — Medium): The vulnerability allows Cross-Site Scripting.
These vulnerabilities collectively present severe security risks to global enterprises using HCL BigFix Service Management for IT endpoint administration.
We recommend you to update HCL BigFix Service Management to version 27 and given link: https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133782
The following reports contain further technical details:
[/emaillocker]