CVE-2026-21785
HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy
CVSS Score
4.0
EPSS Score
0.0%
EPSS Percentile
7th
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.
| CWE | CWE-1021 |
| Vendor | hclsoftware |
| Product | bigfix remote control server |
| Published | May 27, 2026 |
| Last Updated | May 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for hclsoftware bigfix remote control server
Be the first to know when new medium vulnerabilities affecting hclsoftware bigfix remote control server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
HCLSoftware / BigFix Remote Control Server
<= versions 10.1.0.0442