---
id: CVE-2026-56599
title: >-
  HCL BigFix Service Management is affected by an Insecure Cookie Attribute
  Configuration vulnerability, which could allow an attacker to exploit missing
  security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths,
  enabli…
summary: >-
  HCL BigFix Service Management is affected by an Insecure Cookie Attribute
  Configuration vulnerability, which could allow an attacker to exploit missing
  security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths,
  enabli…
severity: low
cvss: 2.2
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-614
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management Version 27
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:30.507'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56599'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-01T15:17:19.902433Z'
ingestedAt: '2026-10-01T15:48:17.814Z'
---

## Overview

HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting (XSS), and unauthorized access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
