HCL BigFix Service Management: Eight Vulnerabilities Disclosed, Including Insecure Communication and XSS
Key findings • Eight vulnerabilities in HCL BigFix Service Management disclosed on October 1, 2026, ranging from Low to High severity. • Multiple information disclosure flaws allow attackers …

Key findings
- Eight vulnerabilities in HCL BigFix Service Management disclosed on October 1, 2026, ranging from Low to High severity.
- Multiple information disclosure flaws allow attackers to access sensitive internal data and discover hidden API endpoints.
- High severity vulnerabilities include insecure communication enabling MitM attacks and stored XSS for session hijacking.
- Improper input validation and insecure cookie configurations also present risks.
- The batch of vulnerabilities was disclosed within a tight two-hour window.
On October 1, 2026, HCL Software disclosed eight vulnerabilities affecting its BigFix Service Management product. The vulnerabilities, disclosed within a two-hour window, span a range of severity levels, from Low to High, with several related to information disclosure and insecure communication. These issues could collectively allow attackers to gain unauthorized access to sensitive data, facilitate further attacks, and potentially compromise user sessions.
Several vulnerabilities center on information disclosure. CVE-2026-67172, a Low severity flaw, involves sensitive information being returned in error messages. Similarly, CVE-2026-67171 and CVE-2026-67106, both Medium severity, stem from exposed API endpoints that leak sensitive internal database information or other sensitive data, respectively. CVE-2026-67104, also Medium severity, allows unauthenticated attackers to discover hidden administrative API endpoints by analyzing publicly accessible JavaScript files.
Another significant concern is CVE-2026-67105, a High severity Insecure Communication vulnerability. This flaw could enable an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, leading to man-in-the-middle attacks and the extraction of sensitive data.
The batch also includes an Improper Input Validation vulnerability, CVE-2025-31980 (Medium severity), which could allow an attacker to inject malformed data, potentially leading to injection attacks or errors in downstream systems. A Stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-56589 (High severity), allows attackers to inject malicious scripts that execute when a victim views an affected page, enabling session hijacking and data theft. Finally, CVE-2026-56599, a Low severity vulnerability, relates to insecure cookie attribute configuration, potentially enabling Cross-Site Request Forgery (CSRF) and session hijacking.
The disclosed vulnerabilities affect various aspects of BigFix Service Management, with multiple issues stemming from API endpoint exposure and improper handling of data. The range of severities indicates a broad impact, with High severity flaws like CVE-2026-67105 and CVE-2026-56589 posing the most immediate risks. Users are advised to consult HCL Software's official advisories for specific remediation steps and affected version information.
Addressing these vulnerabilities is crucial for maintaining the security posture of BigFix Service Management deployments. The information disclosure flaws, in particular, could provide attackers with valuable intelligence to plan more sophisticated attacks. The presence of both insecure communication and XSS vulnerabilities highlights the need for a comprehensive security review of the application's data handling and communication protocols. Users should prioritize patching and review their configurations to mitigate these risks.