---
id: CVE-2026-67100
title: >-
  HCL BigFix Service Management is affected by SQL Injection flaw and a
  Cross-Tenant Data Exposure flaw vulnerabilities
summary: >-
  HCL BigFix Service Management is affected by SQL Injection flaw and a
  Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an
  authenticated attacker to inject database commands to extract sensitive system
  details, as well a…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
  - CWE-200
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management V23
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:11.110'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67100'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133782
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-18T17:31:31.736735Z'
epss: 0.00353
epssPercentile: 0.28995
ingestedAt: '2026-09-18T08:38:04.102Z'
---

## Overview

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
