---
id: CVE-2026-67104
title: >-
  HCL BigFix Service Management is affected by an Information Disclosure
  vulnerability, which could allow an unauthenticated attacker to analyze
  publicly accessible JavaScript files, enabling the discovery of hidden
  administrative API endp…
summary: >-
  HCL BigFix Service Management is affected by an Information Disclosure
  vulnerability, which could allow an unauthenticated attacker to analyze
  publicly accessible JavaScript files, enabling the discovery of hidden
  administrative API endp…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-798
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management Version 27
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:31.107'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67104'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-01T15:17:34.162341Z'
ingestedAt: '2026-10-01T15:48:17.815Z'
---

## Overview

HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
