Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations. | |
| Title | HCL BigFix Service Management is affected by multiple security vulnerabilities. | |
| Weaknesses | CWE-200 CWE-89 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-09-18T07:53:02.676Z
Reserved: 2026-07-28T13:24:18.240Z
Link: CVE-2026-67100
No data.
Status : Received
Published: 2026-09-18T08:17:00.603
Modified: 2026-09-18T08:17:00.603
Link: CVE-2026-67100
No data.
OpenCVE Enrichment
No data.
