CVE-2026-67100
Last modified
CVE-2026-67100 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations..
Description
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| HCL Software | HCL BigFix Service Management | V23 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-67100?
How severe is CVE-2026-67100?
How do I fix CVE-2026-67100?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6704The Blog Settings plugin for WordPress is vulnerable to Refl…6.1
- CVE-2026-6706Improper access control in the vault documentation feature …6.5
- CVE-2026-67071HCL DevOps Deploy / HCL Launch is susceptible to an informat…6.5
- CVE-2026-6708The HEL Online Classroom: AI-powered Online Classrooms plugi…5.3
- CVE-2026-6709The Coinbase Commerce for Contact Form 7 plugin for WordPres…4.3
- CVE-2026-6710The Skysa Text Ticker App plugin for WordPress is vulnerable…4.3
- CVE-2026-67101HCL BigFix Service Management is affected by a Server-Side R…9.3
- CVE-2026-67102HCL BigFix Service Management is affected by a high-severity…8.1
- CVE-2026-67103HCL BigFix Service Management is affected by Cross-Site Scri…7.6
- CVE-2026-6711The Website LLMs.txt plugin for WordPress is vulnerable to R…6.1
- CVE-2026-6712The Website LLMs.txt plugin for WordPress is vulnerable to S…4.4
- CVE-2026-6713GitLab has remediated an issue in GitLab CE/EE affecting all…5.3
Are you affected by CVE-2026-67100?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
