---
id: CVE-2026-56595
title: >-
  HCL BigFix Service Management is affected by a CORS Misconfiguration
  vulnerability due to improperly validated origin headers, which could allow an
  attacker to craft a malicious web page that interacts with the vulnerable
  application, en…
summary: >-
  HCL BigFix Service Management is affected by a CORS Misconfiguration
  vulnerability due to improperly validated origin headers, which could allow an
  attacker to craft a malicious web page that interacts with the vulnerable
  application, en…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-942
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management v27
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:44:57.517'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56595'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133917
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
epss: 0.00148
epssPercentile: 0.04404
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T10:50:01.222730Z'
ingestedAt: '2026-09-18T08:38:04.113Z'
---

## Overview

HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a malicious web page that interacts with the vulnerable application, enabling unauthorized access to protected resources and restricted APIs on behalf of a victim.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
