OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-56589

HIGH · CVSS 7.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

HCL BigFix Service Management is vulnerable to a Stored Cross-Site Scripting (XSS) flaw that allows attackers to inject malicious scripts, which execute when a user accesses the compromised page. This could lead to session hijacking and the theft of sensitive information. Organizations using this application should prioritize remediation to protect against potential data breaches and unauthorized access.

CVE
CVE-2026-56589
Severity
HIGH
CVSS
7.2
EPSS
0.20%

Original NVD Description

HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.

Related CVEs

Other vulnerabilities affecting the same vendor(s)