---
id: CVE-2026-67105
title: >-
  HCL BigFix Service Management is affected by an Insecure Communication
  vulnerability, which could allow an attacker with internal network access to
  intercept unencrypted HTTP traffic between backend services, enabling the
  extraction of s…
summary: >-
  HCL BigFix Service Management is affected by an Insecure Communication
  vulnerability, which could allow an attacker with internal network access to
  intercept unencrypted HTTP traffic between backend services, enabling the
  extraction of s…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-319
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management Version 27
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:31.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67105'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-01T15:20:22.122219Z'
ingestedAt: '2026-10-01T15:48:17.815Z'
---

## Overview

HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
