OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-67172

LOW · CVSS 3.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

HCL BigFix Service Management is vulnerable to an Information Disclosure flaw that exposes sensitive information through error messages when invalid inputs are submitted to specific API endpoints. This vulnerability could assist attackers in executing further attacks by leveraging the disclosed data. Organizations using HCL BigFix should prioritize addressing this issue to mitigate potential risks associated with unauthorized access to sensitive information.

CVE
CVE-2026-67172
Severity
LOW
CVSS
3.7
EPSS
0.21%

Original NVD Description

HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)