CVE-2026-67100
9.8HCL Software · HCL BigFix Service Management
HCL BigFix Service Management contains SQL injection and cross-tenant data exposure flaws, allowing attackers to extract sensitive system information and access unauthorized PII across organizations.
Executive summary
A critical SQL injection and data exposure vulnerability in HCL BigFix Service Management poses a severe risk of unauthorized PII access and system compromise.
Vulnerability
The application is susceptible to SQL injection (CWE-89) and cross-tenant data exposure, which allows an attacker to execute arbitrary database commands and manipulate request parameters. While the description references authenticated access, the CVSS vector (PR:N) indicates these flaws are exploitable by an unauthenticated attacker.
Business impact
The potential for unauthorized access to personal profile data and PII across multiple organizations represents a significant compliance and reputational risk. Given the CVSS score of 9.8, this vulnerability facilitates full system compromise, including the ability to exfiltrate sensitive data and manipulate backend database contents.
Remediation
Immediate Action: Consult the official HCL support portal at the provided reference link to determine if a security update is available for your specific deployment of V23.
Proactive Monitoring: Review application and database access logs for anomalous SQL queries or unexpected cross-tenant request patterns.
Compensating Controls: Implement a robust Web Application Firewall (WAF) to detect and block common SQL injection patterns and restrict unauthorized cross-tenant traffic at the network edge.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is classified as critical due to the potential for large-scale data exfiltration and total system compromise. Administrators must prioritize investigating the HCL support portal for an available patch and apply it immediately upon release to mitigate the exposure of organizational PII.
More HCL Software CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section