---
id: CVE-2026-67106
title: >-
  HCL BigFix Service Management is affected by an Information Disclosure
  vulnerability because two exposed API endpoints return sensitive data
summary: >-
  HCL BigFix Service Management is affected by an Information Disclosure
  vulnerability because two exposed API endpoints return sensitive data. This
  information could enable an attacker to launch further, more serious attacks.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-209
vendor: HCL Software
product: HCL BigFix Service Management
affected:
  - hcl_bigfix_service_management Version 27
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:17:31.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-67106'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015
    label: psirt@hcl.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-01T15:17:11.124016Z'
ingestedAt: '2026-10-01T15:48:17.815Z'
---

## Overview

HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
