๐Ÿ” CVE Alert

CVE-2026-21785

MEDIUM 4.0

HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content Security Policy

CVSS Score
4.0
EPSS Score
0.0%
EPSS Percentile
7th

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

CWE CWE-1021
Vendor hclsoftware
Product bigfix remote control server
Published May 27, 2026
Last Updated May 28, 2026
Stay Ahead of the Next One

Get instant alerts for hclsoftware bigfix remote control server

Be the first to know when new medium vulnerabilities affecting hclsoftware bigfix remote control server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

HCLSoftware / BigFix Remote Control Server
<= versions 10.1.0.0442

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.hcl-software.com: https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130581