---
id: CVE-2026-67101
title: >-
  HCL BigFix Service Management is affected by a Server-Side Request Forgery
  (SSRF) vulnerability in its search functionality, which could allow an
  attacker to force the application server to send requests to internal systems
  that are not …
summary: >-
  HCL BigFix Service Management is affected by a Server-Side Request Forgery
  (SSRF) vulnerability in its search functionality, which could allow an
  attacker to force the application server to send requests to internal systems
  that are not …
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'
cwe:
  - CWE-918
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management V23
published: '2026-09-18'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T19:17:09.017'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67101'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0133782
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
epss: 0.00268
epssPercentile: 0.19232
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-21T18:13:08.816315Z'
ingestedAt: '2026-09-18T08:38:04.103Z'
---

## Overview

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
