---
id: CVE-2026-56590
title: >-
  HCL BigFix Service Management is affected by an Unrestricted File Upload
  vulnerability due to improper file validation controls, which could allow an
  unauthenticated attacker to upload and execute malicious payloads, resulting
  in a compl…
summary: >-
  HCL BigFix Service Management is affected by an Unrestricted File Upload
  vulnerability due to improper file validation controls, which could allow an
  unauthenticated attacker to upload and execute malicious payloads, resulting
  in a compl…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-434
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management v27
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:17:17.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56590'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133917
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
epss: 0.0017
epssPercentile: 0.06778
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T19:11:36.026646Z'
ingestedAt: '2026-09-18T08:38:04.115Z'
---

## Overview

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complete server compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
