← Back to CVE List
CVE-2026-21848NVD
Description
HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized viewing of restricted data elements across tenant boundaries.
CVSS Base Metrics
CVSS v3 (3.1)
MEDIUM 5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Weaknesses (CWE)
CWE-284 - CWE-284 Improper Access Control
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| HCL Software HCL BigFix Service Management | V23 | N/A |