---
id: CVE-2026-56597
title: >-
  HCL BigFix Service Management is affected by a Sensitive Information Leakage
  vulnerability, which could allow an unauthenticated attacker to extract
  internal IP addresses from the application's responses, enabling them to map
  the underly…
summary: >-
  HCL BigFix Service Management is affected by a Sensitive Information Leakage
  vulnerability, which could allow an unauthenticated attacker to extract
  internal IP addresses from the application's responses, enabling them to map
  the underly…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management v27
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:44:57.517'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56597'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133917
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
epss: 0.00159
epssPercentile: 0.05454
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T11:10:24.889452Z'
ingestedAt: '2026-09-18T08:38:04.113Z'
---

## Overview

HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
