CVE-2026-21765
8.8HCLSoftware · BigFix Platform
HCL BigFix Platform on Windows hosts contains insecure file system permissions on private cryptographic keys, potentially allowing local attackers to access sensitive material.
Executive summary
HCL BigFix Platform versions 11.0.0 through 11.0.5 are vulnerable to insecure file system permissions on critical cryptographic keys, presenting a risk of unauthorized access to sensitive data.
Vulnerability
This vulnerability involves incorrect permission assignment for critical resources (CWE-732), where private cryptographic keys on Windows hosts are stored with overly permissive access rights. An attacker with local access to the system can exploit these permissions to gain unauthorized access to the keys.
Business impact
The exposure of private cryptographic keys can lead to a complete compromise of the confidentiality, integrity, and availability of the affected system. Given the CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it could facilitate further lateral movement or the decryption of sensitive communications and data. Unauthorized access to these keys undermines the fundamental security posture of the BigFix deployment.
Remediation
Immediate Action: Review the HCL security advisory (KB0129906) and apply the vendor-provided security updates or configuration hardening steps as soon as they become available.
Proactive Monitoring: Monitor system access logs for any unauthorized attempts to access sensitive file paths associated with BigFix configuration and cryptographic assets.
Compensating Controls: Restrict local user access to the host machines running BigFix to only necessary personnel, and implement strict file system auditing to detect unauthorized read access to key files.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability carries a high severity rating, and organizations should prioritize securing the file system environment where the BigFix Platform is deployed. Administrators must audit existing permissions on the affected Windows hosts and apply vendor-recommended configurations to restrict access to cryptographic keys immediately. Failure to remediate this issue increases the risk of privilege escalation and systemic compromise.